Skip to content

chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate - #89

Merged
hyperpolymath merged 2 commits into
mainfrom
chore/actions-lock-generate
Oct 1, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
chore/actions-lock-generate

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

  • Adds .github/workflows/actions.lock. It was generated by gh actions-lock --no-narrow v0.1.6 from the refs already SHA-pinned here, so no uses: line changes.
  • Moves the tool's banner to line 2 in each workflow, keeping SPDX on line 1.

Why

From 2026-10-01 the governance "Actions lockfile verify" gate fails any repo that lacks a lockfile. Changing the date on standards main would not help, because this repo pins the reusable workflow by SHA.

Verification

  • The gate script at the pinned standards SHA passes with LOCK_TODAY=2026-10-01.
  • This PR's own runs are the runtime test. Every workflow must create jobs, with no startup_failure.

🤖 Generated with Claude Code

https://claude.ai/code/session_019aa9y32JcBuZ85KXe2jb8R

The governance "Actions lockfile verify" gate requires
.github/workflows/actions.lock from 2026-10-01. Every ref here is already
SHA-pinned; `gh actions-lock --no-narrow` (v0.1.6) records those same SHAs
and their transitive composite deps, with no ref rewritten.

The tool's "managed by gh actions-lock" banner is placed on line 2 so SPDX
stays on line 1.

Verified locally: the gate script at the pinned standards SHA passes with
LOCK_TODAY=2026-10-01.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019aa9y32JcBuZ85KXe2jb8R
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9738f9d6-7b49-453d-b857-9a697ba6af11

📥 Commits

Reviewing files that changed from the base of the PR and between 56c81bd and e21117d.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (16)
  • .github/workflows/cflite_batch.yml
  • .github/workflows/cflite_pr.yml
  • .github/workflows/ci.yml
  • .github/workflows/codeql.yml
  • .github/workflows/dependabot-automerge.yml
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/label-triage.yml
  • .github/workflows/labels.yml
  • .github/workflows/makefile-blocker.yml
  • .github/workflows/mirror.yml
  • .github/workflows/pages.yml
  • .github/workflows/push-email-notify.yml
  • .github/workflows/rust-ci.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (26)
  • GitHub Check: rust-ci / Detect Cargo.toml
  • GitHub Check: secret-scan / gitleaks
  • GitHub Check: secret-scan / shell-secrets
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: secret-scan / rust-secrets
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Live Actions policy (credentialed advisory)
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: Test (3.12)
  • GitHub Check: Build Documentation
  • GitHub Check: Test (3.10)
  • GitHub Check: Test (3.11)
  • GitHub Check: Security Scan
  • GitHub Check: analyze (cpp, none)
  • GitHub Check: analyze (javascript-typescript, none)
  • GitHub Check: semgrep-cloud-platform/scan
⚠️ CI failures not shown inline (9)

GitHub Actions: CodeQL Security Analysis / 0_analyze (cpp, none).txt: chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Extracting cpp
 [command]/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/codeql database trace-command --use-build-mode --working-dir /home/runner/work/dicti0nary-attack/dicti0nary-attack /home/runner/work/_temp/codeql_databases/cpp
 Running command in /home/runner/work/dicti0nary-attack/dicti0nary-attack: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh]
 [] [build-stdout] Overlay mode: full (enabled: false)
 [] [build-stdout] Using 4 threads for extraction
 [] [build-stdout] Indexed folder "/home/runner/work/dicti0nary-attack/dicti0nary-attack", found 0 source files, 0 header files, 224 total files.
 [] [build-stdout] Extraction failed: No source files found.
 [] [build-stderr] cpp/autobuilder: autobuild summary.
 [] [ERROR] Spawned process exited abnormally (code 1; tried to run: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh])
 A fatal error occurred: Exit status 1 from command: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh]
 ##[error]Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/codeql database trace-command --use-build-mode --working-dir /home/runner/work/dicti0nary-attack/dicti0nary-attack /home/runner/work/_temp/codeql_databases/cpp". Exit code was 2 and error was: A fatal error occurred: Exit status 1 from command: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh]. See the logs for more details.

GitHub Actions: CodeQL Security Analysis / analyze (cpp, none): chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Extracting cpp
 [command]/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/codeql database trace-command --use-build-mode --working-dir /home/runner/work/dicti0nary-attack/dicti0nary-attack /home/runner/work/_temp/codeql_databases/cpp
 Running command in /home/runner/work/dicti0nary-attack/dicti0nary-attack: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh]
 [] [build-stdout] Overlay mode: full (enabled: false)
 [] [build-stdout] Using 4 threads for extraction
 [] [build-stdout] Indexed folder "/home/runner/work/dicti0nary-attack/dicti0nary-attack", found 0 source files, 0 header files, 224 total files.
 [] [build-stdout] Extraction failed: No source files found.
 [] [build-stderr] cpp/autobuilder: autobuild summary.
 [] [ERROR] Spawned process exited abnormally (code 1; tried to run: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh])
 A fatal error occurred: Exit status 1 from command: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh]
 ##[error]Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/codeql database trace-command --use-build-mode --working-dir /home/runner/work/dicti0nary-attack/dicti0nary-attack /home/runner/work/_temp/codeql_databases/cpp". Exit code was 2 and error was: A fatal error occurred: Exit status 1 from command: [/opt/hostedtoolcache/CodeQL/2.27.1/x64/codeql/cpp/tools/autobuild.sh]. See the logs for more details.

GitHub Actions: CI/CD Pipeline / 2_Test (3.12).txt: chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 �[36;1mpip install -e .�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.12.14/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.12.14/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.12.14/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.12.14/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.12.14/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.12.14/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.12.14/x64/lib/python3.12/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.

GitHub Actions: CI/CD Pipeline / 3_Build Documentation.txt: chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.11.16/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.11.16/x64/lib/python3.11/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.

GitHub Actions: CI/CD Pipeline / Build Documentation: chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.11.16/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.11.16/x64/lib/python3.11/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.

GitHub Actions: CI/CD Pipeline / 5_Test (3.11).txt: chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 �[36;1mpip install -e .�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.11.16/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.11.16/x64/lib/python3.11/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.

GitHub Actions: CI/CD Pipeline / Test (3.11): chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 �[36;1mpip install -e .�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.11.16/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.11.16/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.11.16/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.11.16/x64/lib/python3.11/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.

GitHub Actions: CI/CD Pipeline / 6_Test (3.10).txt: chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 �[36;1mpip install -e .�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.10.21/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.10.21/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.21/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.21/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.21/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.10.21/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.10.21/x64/lib/python3.10/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.

GitHub Actions: CI/CD Pipeline / Test (3.10): chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate

Conclusion: failure

View job details

##[group]Run python -m pip install --upgrade pip
 �[36;1mpython -m pip install --upgrade pip�[0m
 �[36;1mpip install -r requirements.txt�[0m
 �[36;1mpip install -e .�[0m
 shell: /usr/bin/bash -e {0}
 env:
   pythonLocation: /opt/hostedtoolcache/Python/3.10.21/x64
   PKG_CONFIG_PATH: /opt/hostedtoolcache/Python/3.10.21/x64/lib/pkgconfig
   Python_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.21/x64
   Python2_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.21/x64
   Python3_ROOT_DIR: /opt/hostedtoolcache/Python/3.10.21/x64
   LD_LIBRARY_PATH: /opt/hostedtoolcache/Python/3.10.21/x64/lib
 ##[endgroup]
 Requirement already satisfied: pip in /opt/hostedtoolcache/Python/3.10.21/x64/lib/python3.10/site-packages (26.2.1)
 ERROR: Could not open requirements file: [Errno 2] No such file or directory: 'requirements.txt'
 ##[error]Process completed with exit code 1.
🔇 Additional comments (16)
.github/workflows/cflite_batch.yml (1)

2-2: LGTM!

.github/workflows/cflite_pr.yml (1)

2-2: LGTM!

.github/workflows/ci.yml (1)

2-2: LGTM!

.github/workflows/codeql.yml (1)

2-2: LGTM!

.github/workflows/dependabot-automerge.yml (1)

2-2: LGTM!

.github/workflows/governance.yml (1)

2-2: LGTM!

.github/workflows/hypatia-scan.yml (1)

2-2: LGTM!

.github/workflows/label-triage.yml (1)

2-2: LGTM!

.github/workflows/labels.yml (1)

2-2: LGTM!

.github/workflows/makefile-blocker.yml (1)

2-2: LGTM!

.github/workflows/mirror.yml (1)

2-2: LGTM!

.github/workflows/pages.yml (1)

2-2: LGTM!

.github/workflows/push-email-notify.yml (1)

2-2: LGTM!

.github/workflows/rust-ci.yml (1)

2-2: LGTM!

.github/workflows/scorecard.yml (1)

2-2: LGTM!

.github/workflows/secret-scanner.yml (1)

2-2: LGTM!


📝 Summary

Summary by CodeRabbit

  • Documentation
    • Added notes identifying automated workflows as managed by an action-locking tool. Workflow behaviour is unchanged.

Walkthrough

Added a comment identifying 16 GitHub Actions workflows as managed by gh actions-lock. The workflow behaviour did not change.

Changes

Workflow management comments

Layer / File(s) Summary
Add workflow management comments
.github/workflows/*.yml
Added a comment identifying each changed workflow as managed by gh actions-lock. No executable workflow behaviour changed.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to e2111

This change records pinned actions and adds workflow comments; the pinned gate intentionally allows the reusable-workflow callers to be omitted from the lock. No material merge risk is evident.

Architecture Summary

Architecture risk: 🔵 Low · up to e2111

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/cflite_batch.yml: Added a comment stating that this workflow is managed by gh actions-lock.
  • observed — Modified behavior in .github/workflows/cflite_pr.yml: Added a comment identifying the workflow as managed by gh actions-lock.
  • observed — Modified behavior in .github/workflows/ci.yml: Added a comment identifying the workflow as managed by gh actions-lock.
  • observed — Modified behavior in .github/workflows/codeql.yml: Adds a comment identifying the workflow as managed by gh actions-lock.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the lockfile change, the reason for the change, and the reported verification. However, it does not follow the repository template and omits most required sections, including … Update the description to use the repository template. Complete the required sections and checkboxes, record the applicable CI/CD improvement type, add related issue information or state that none applies, list the changes, document test co…
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: generating the actions lockfile before the 1 October 2026 lock gate.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the lockfile change, the reason for the change, and the reported verification. However, it does not follow the repository template and omits most required sections, including Type of Change, Related Issues, Changes Made, Testing checkboxes and results, checklists, performance impact, breaking changes, reviewer checklist, and confirmation statements.

Resolution

Update the description to use the repository template. Complete the required sections and checkboxes, record the applicable CI/CD improvement type, add related issue information or state that none applies, list the changes, document test commands and results, complete the relevant quality, security, RSR, legal, performance, and breaking-change sections, and retain the verification details.

🤖 Coding task started

✨ Finishing Touches
🛠️ Fix failing CI checks
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads each workflow line,
And finds a note that marks its sign.
No tasks have changed, no steps now run,
Just comments added, one by one.
The rabbit hops beneath the moon,
And checks the workflows, all in tune.

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Autopilot could not be updated. Open Coding to check access and billing.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

✅ Coding Agent task started: View task and status

The task will inspect the CI failures, validate its fix, and commit the fix to this branch automatically.

Note: Fixing CI failures is a beta feature and may encounter errors. Expect some limitations and changes as we gather feedback and continue to improve it.

⏭️ 2 check(s) skipped — already failing on `main` (not caused by this PR)
  • GitHub Actions: CodeQL Security Analysis / 0_analyze (cpp, none).txt
  • GitHub Actions: Rust CI / 1_rust-ci _ Coverage (tarpaulin + codecov).txt

@hyperpolymath
hyperpolymath merged commit 9bf3e4e into main Oct 1, 2026
24 of 32 checks passed
@hyperpolymath
hyperpolymath deleted the chore/actions-lock-generate branch October 1, 2026 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant