Repository navigation
fix(lock): relock actions.lock after the rust-toolchain bump (#1157) - #1160
Conversation
#1157 bumped dtolnay/rust-toolchain to 7e38f4b in mirror-reusable.yml and rust-ci-reusable.yml without regenerating .github/workflows/actions.lock and merged with all four lock contexts red (only scan / gitleaks is required on main). GitHub validates a reusable callee's lock at the pinned SHA, so every caller pinned at or after 8556163 dies at startup (conclusion failure, jobs=0, no check-run) - measured on metadatastician/ZenodoDeposits.jl#13. Regenerated with the estate repair order, no hand edits: gh actions-lock -> relock-sha-keys.sh -> complete-job-refs.sh -> close-lock.sh -> prune-stale.sh, every file except the lock restored. Net effect against 5751b97: - mirror-reusable.yml and rust-ci-reusable.yml entries move from 02cb101 to 7e38f4b; the orphaned 02cb101 record is retired, a 7e38f4b record added. - close-lock adds the missing dependencies record for 571cc734, which mirror.yml and ci-pipeline.yml named without one. On main mirror.yml dies at startup with "Invalid lockfile" and self-ci.yml (which calls ci-pipeline.yml) creates no jobs; the mirror.yml dispatch on this branch is the test of that cure. - The duplicate actions/checkout@v7.0.1 key is merged into the SHA key; setup-zig and harden-runner refs are normalised to their SHA form. - The orphan Asana/push-signed-commits@d615ca8 record (named by no workflow entry; its nested actions/setup-python@v2 had no record) is dropped by gh actions-lock. signed-push-smoke.yml's entry is unchanged. Local gates on this lock: update-actions-lock.sh --verify-local rc=0, check-lock-sync.sh rc=0, check-actions-lock-gate.sh rc=0. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37470261389 K9 normative contract typecheckK9 contract self-testK9 conformance fixtures |
|
|
Add Carrot credits or activate Agent usage billing to use Autopilot |
|
The relock drops a composite-action dependency.
The likely cause is a regenerate run with Found while stacking a fix for a silent 🤖 Generated with Claude Code |
…1162) ## Summary Restores the `Asana/push-signed-commits` entry that the #1160 relock dropped from `.github/workflows/actions.lock`. The composite action `.github/actions/signed-push/action.yml:42` still uses it. Since ce92a8c, `uses ⊆ actions.lock` on main has failed with `not in actions.lock: Asana/push-signed-commits@d615ca88…`. This is the defect raised on #1160 in issuecomment-6017428696, which was posted the minute it merged. Main has no linked issue for it; the red check on main is the record. ## Type of change - [x] 🐛 Bug fix: main is red on `uses ⊆ actions.lock`. - [ ] ✨ New feature: not applicable. - [ ] 💥 Breaking change: not applicable. The entry existed until ce92a8c. - [ ] 🕳️ Soundness fix: not applicable. - [ ] 📖 Documentation: not applicable. - [ ] 🧹 Refactor: not applicable. - [ ] ⚡ Performance: not applicable. - [x] 🔧 Build / CI / tooling ## 📌 New pins - Head SHA: **e4641cae27a56264ea3e731d893a07ed5bbbe03b** - **Asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897** (ref **v1.3**, owner_id 1472111, repo_id 772313726, transitive `actions/setup-python@v2`). This is a restored entry, byte-identical to the one on 5751b97; it adds no new pin. No workflow YAML is changed. ## How has this been verified? - `bash .githooks/validate-actions-lock.sh` on ce92a8c: **rc=1**, `1 ref(s) missing from the lockfile` (Asana). With this change: **rc=0**, `26 SHA-pinned ref(s) found among 26 lockfile keys`. - `./scripts/check-lock-sync.sh` gives **rc=0**: every `uses:` is locked, and every entry is referenced. - `git diff 5751b97 -- .github/workflows/actions.lock` shows no Asana lines, so the restored block matches the pre-#1160 one exactly. ## Checklist - [x] My commits are **signed**: `git log --format=%G?` gives `G`. - [x] I ran the project's own checks locally and they pass (the two lock scripts above; the pre-commit hook accepted the commit). - [ ] New files carry the correct SPDX identifier: not applicable, no new files. - [ ] Docs are updated: not applicable, no documentation claim is affected. - [x] I have not introduced a soundness hole. This adds back a lock entry; it removes no check. ## Notes for reviewers Main's other reds on ce92a8c are unrelated to this lock entry and are not touched here: Repo self-tests, Registry + topology, K9-SVC, Haskell pipeline, Hypatia scan/baseline, Allowlist Preflight, and SonarCloud. `gh actions-lock --no-fix --verify` also reports a `local-action` error for `signed-push-smoke.yml` (`uses: ./…`). That error is pre-existing on 5751b97 and is a tool opinion, not a GitHub validation. It is left alone. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7 Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>



Summary
Regenerates
.github/workflows/actions.lockwith the estate repair order after #1157 bumpeddtolnay/rust-toolchainto7e38f4binmirror-reusable.ymlandrust-ci-reusable.ymlwithout relocking. #1157 merged with all four lock contexts red because onlyscan / gitleaksis required onmain(ruleset 23787415, which carries the lock contexts, is disabled). GitHub validates a reusable callee's lock at the pinned SHA, so every external caller pinned at or after8556163dies at startup (conclusionfailure, jobs=0, no check-run, invisible in the PR UI) — measured on metadatastician/ZenodoDeposits.jl#13, whosemirror.ymlis pinned back toef7e6c4until this lands.No hand edits.
gh actions-lock(v0.1.6) →scripts/relock-sha-keys.sh→scripts/complete-job-refs.sh→scripts/close-lock.sh→scripts/prune-stale.sh, then every file except the lock restored — thescripts/regen-dependabot-locks.shorder. The lock is the only file changed (+13 / −20).Net effect against
5751b97:mirror-reusable.ymlandrust-ci-reusable.ymlentries move02cb101→7e38f4b; the orphaned02cb101record is retired and a7e38f4brecord added. This is the fix external callers need.close-lock.shadds adependencies:record forhyperpolymath/standards@571cc734, whichmirror.ymlandci-pipeline.ymlhave named since Pr 1148 #1153 without one.actions/checkout@v7.0.1key is merged into the3d3c42e5…SHA key;setup-zigandharden-runnerref:fields are normalised to SHA form (keys and digests unchanged).asana/push-signed-commits@d615ca8record (named by no workflow entry; its nestedactions/setup-python@v2had no record) is dropped bygh actions-lock.signed-push-smoke.yml's entry is byte-identical tomain.What this PR does not fix — measured, not inferred. standards' own
mirror.yml(andself-ci.yml, viaci-pipeline.yml) has died at startup on every push since5693b8b(#1153, 2026-10-05 06:47Z), the commit that addedhyperpolymath/standards@571cc734to those two lock entries. Themirror.ymlrun before it (6075712) created 7 jobs. Aworkflow_dispatchofmirror.ymlon this branch (run 37469615969) is stillstartup_failure, but the run-page error changed:mirror.ymlmain: namesstandards@571cc734, no recordstartup_failureInvalid lockfile: The lockfile could not be validated. Regenerate it by running gh actions-lockuses:startup_failurelockfile missing pin for actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1actions/checkout@3d3c42e5is the first step-level pin ofmirror-reusable.ymlat571cc734. So GitHub resolves the pinned callee and checks its pins against the caller's record, and the estate chain writes job-level records without them (build-dep-records.sh, the tool that would, is not onmain). The callee lock at571cc734is itself valid:gh actions-lock --no-fixin a checkout of571cc734reports only the pre-existing local-action complaint. Howmirror.yml/ci-pipeline.ymlshould pin their reusables is a separate decision put to the owner; this PR is complete for its stated purpose.Type of change
📌 New pins
Head SHA:
c9f2afa83465ac09c3eab5427b3938ef167bedbdAll changes are inside
.github/workflows/actions.lock; nouses:line, container digest or other lockfile changed.dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067— record added (ref: v1; the workflows annotate the pin# stable), listed undermirror-reusable.ymlandrust-ci-reusable.ymlin place of02cb101ec7c40f2c49e1d9714d64511d8e1b74de, whose record is retired.hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd— leaf record added for the existing job-level pin inmirror.ymlandci-pipeline.yml(no nesteduses:, see above).actions/checkout@v7.0.1(duplicate of the3d3c42e5aac5ba805825da76410c181273ba90b1key),asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897(orphan).ref:normalised to the SHA form onactions/checkout@3d3c42e5…,goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406,step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1.How has this been verified?
The pull_request checks on this PR are the test for its purpose:
governance / Actions lockfile verify,uses ⊆ actions.lock,Lockfile self-consistencyandactions.lock is in sync with the workflow YAMLwere all red onmain5751b97and on #1157's head7d1dc688. This section is updated once they report onc9f2afa8.Checklist
git log --show-signatureshowsG).maineither.uses:for job-level records, somirror.ymlstays dead; the only composite-related change is the removal of an unreferenced record.Notes for reviewers
required_linear_history). Jonathan merges.mainrequiresgovernance / Actions lockfile verifyanduses ⊆ actions.lockwith no bypass actors, so a red lock gate cannot be merged over again (owner decision, 2026-10-06; applied by Claude with a planted positive control).dev-notes/inbox/findings.md(D273), not as new issues.Post-merge note, 2026-10-06. This PR was squash-merged at
c9f2afaasce92a8c. It dropped theasana/push-signed-commits@d615ca88…record, becausegh actions-lockdoes not scan.github/actions/*/action.yml(#1122). That record is not an orphan:.github/actions/signed-push/action.yml:42needs it. #1163 re-added it, and all four lock contexts are green onmain44a0de4. A follow-up commit,596ba74, was pushed after the merge and is superseded. It was never part of this PR. Red checks on this PR that it did not cause are tracked in #955, #994, #934 and #1161.🤖 Generated with Claude Code
https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw