chore(deps): bump the actions group with 14 updates - #107
Merged
Merged
Conversation
Bumps the actions group with 14 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.1.1` | `7.0.1` | | [haskell-actions/setup](https://github.com/haskell-actions/setup) | `2.7.5` | `2.12.1` | | [actions/cache](https://github.com/actions/cache) | `4.2.0` | `6.1.0` | | [actions/configure-pages](https://github.com/actions/configure-pages) | `5.0.0` | `6.0.0` | | [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) | `3.0.1` | `5.0.0` | | [actions/deploy-pages](https://github.com/actions/deploy-pages) | `4.0.5` | `5.0.1` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.32.6` | `4.38.2` | | [erlef/setup-beam](https://github.com/erlef/setup-beam) | `1.20.4` | `1.24.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` | | [actions/github-script](https://github.com/actions/github-script) | `8.0.0` | `9.0.0` | | [hyperpolymath/smtp-notify-action](https://github.com/hyperpolymath/smtp-notify-action) | `0.2.0` | `0.3.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.1.8` | `8.0.1` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.5.0` | `3.0.3` | | [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) | `2.4.0` | `4.2.2` | Updates `actions/checkout` from 4.1.1 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4.1.1...v7.0.1) Updates `haskell-actions/setup` from 2.7.5 to 2.12.1 - [Release notes](https://github.com/haskell-actions/setup/releases) - [Commits](haskell-actions/setup@v2.7.5...v2.12.1) Updates `actions/cache` from 4.2.0 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4.2.0...v6.1.0) Updates `actions/configure-pages` from 5.0.0 to 6.0.0 - [Release notes](https://github.com/actions/configure-pages/releases) - [Commits](actions/configure-pages@v5.0.0...v6.0.0) Updates `actions/upload-pages-artifact` from 3.0.1 to 5.0.0 - [Release notes](https://github.com/actions/upload-pages-artifact/releases) - [Commits](actions/upload-pages-artifact@v3.0.1...v5.0.0) Updates `actions/deploy-pages` from 4.0.5 to 5.0.1 - [Release notes](https://github.com/actions/deploy-pages/releases) - [Commits](actions/deploy-pages@v4.0.5...v5.0.1) Updates `github/codeql-action` from 4.32.6 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.32.6...v4.38.2) Updates `erlef/setup-beam` from 1.20.4 to 1.24.1 - [Release notes](https://github.com/erlef/setup-beam/releases) - [Commits](erlef/setup-beam@v1.20.4...v1.24.1) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4.6.2...v7.0.1) Updates `actions/github-script` from 8.0.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v8.0.0...v9.0.0) Updates `hyperpolymath/smtp-notify-action` from 0.2.0 to 0.3.0 - [Release notes](https://github.com/hyperpolymath/smtp-notify-action/releases) - [Changelog](https://github.com/hyperpolymath/smtp-notify-action/blob/main/CHANGELOG.adoc) - [Commits](hyperpolymath/smtp-notify-action@v0.2.0...v0.3.0) Updates `actions/download-artifact` from 4.1.8 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4.1.8...v8.0.1) Updates `softprops/action-gh-release` from 2.5.0 to 3.0.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@v2.5.0...v3.0.3) Updates `actions/attest-build-provenance` from 2.4.0 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@v2.4.0...v4.2.2) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: haskell-actions/setup dependency-version: 2.12.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/configure-pages dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-pages-artifact dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/deploy-pages dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: github/codeql-action dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: erlef/setup-beam dependency-version: 1.24.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: hyperpolymath/smtp-notify-action dependency-version: 0.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
hyperpolymath
approved these changes
Oct 4, 2026
hyperpolymath
added a commit
that referenced
this pull request
Oct 5, 2026
…ock gate, K9 pedigree (#108) Closes #103. ## What was actually broken Four independent faults on `main`, all masquerading as one red board. Every one of them was diagnosed from the run pages' own error text, or measured with a throwaway probe workflow, not guessed. ### 1. `actions.lock` drift — the one that killed the required checks Dependabot #107 bumped 14 action tags and left `.github/workflows/actions.lock` describing the old ones. An out-of-date lockfile is not a soft failure: GitHub refuses to **start** every workflow listed in it, with ``` The lockfile could not be validated. Regenerate it by running `gh actions-lock`. ``` so the run ends `startup_failure` with zero steps and **zero check runs**. That is why `ABI Contract` and `Cross-Platform Build & Test` — the producers of the four required contexts — went from green (#104) to nothing at all in a single commit. Two things about the fix are worth stating, because both were got wrong first: * **`--relock` is not "regenerate".** It means *bump moved branch/version refs to their current upstream SHA*, so it re-resolved everything to latest and wrote a lockfile keyed by **tag** (`actions/checkout@v7.0.1`) while every workflow in this repo names a **SHA** (`actions/checkout@3d3c42e5… # v7.0.1`). The estate's validator keys on `owner/repo@<40-hex>` exactly as written, so that file contradicted every workflow in the repo and took the failure count from 2 workflows to *all of them*. The canonical regeneration is plain fix mode with `--no-migrate-local-actions --no-narrow`. * **the lockfile must key on the ref the workflow names.** Measured against `hyperpolymath/standards` `.githooks/validate-actions-lock.sh`: the lockfile on `main` is missing **10 of the 14** required SHA keys. The one here is missing none — 17 refs checked against 17 keys, 0 errors. ### 2. Estate Actions allow-list `goto-bus-stop/setup-zig`, `editorconfig-checker/action-editorconfig-checker`, `webfactory/ssh-agent`, `dtolnay/rust-toolchain` and — measured on this branch — **`haskell-actions/setup`** are all refused: ``` The action … is not allowed in hyperpolymath/game-server-admin because all actions must be from a repository owned by hyperpolymath, created by GitHub, or verified in the GitHub Marketplace. ``` Per the owner's ruling on #103 the allow-list is not widened; the offending `uses:` are replaced. `setup-zig` → `scripts/install-zig.sh` (#104's precedent). `haskell-actions/setup` → `scripts/setup-haskell.sh` (GHC 9.8.2 + cabal 3.10.2.0 from `downloads.haskell.org`, sha256-verified against `ghcup-0.0.7.yaml`). `haskell-actions/setup` deserves a note: Pages' only error was the lockfile, which **masks** action rejections behind it, so it was reverted to the action on the assumption it was fine — then measured with a two-step probe workflow pushed to this branch and deleted again, which got both it and the `editorconfig-checker` control refused in one message. The installer is back. ### 3. K9 pedigree `container/deploy.k9.ncl` had no `pedigree` record. Rewritten with one inline (name, version, `schema_version`, leash, security, target, validation, recipes, warnings). `Validate K9 contracts` is green. ### 4. SonarCloud `SonarCloud Code Analysis` is red on `main` on `new_security_rating = 3` (grade C), driven by five `githubactions:S7637` MAJOR vulnerabilities — *"Use full commit SHA hash for this dependency"* — on `casket-pages.yml`, `hypatia-scan.yml`, `instant-sync.yml`, `release.yml` and `static-analysis-gate.yml`. Those five are exactly what SHA-pinning every `uses:` fixes: the PR head's own Sonar analysis reports **zero** of them. The PR's gate was failing only on a `githubactions:S8233` this PR introduced (workflow-level `pull-requests: write`), now moved to the job that writes. `main` goes green on its first analysis after this merges. ## The gate: `.github/workflows/actions-lock.yml` Regenerating the lockfile fixes today; nothing stopped Dependabot re-breaking it next week. New workflow: * **`verify`** — `gh actions-lock --verify`. Fails when lockfile and workflows disagree, so a bump cannot merge unrelocked. Exit 0 = in sync, 1 = drift, ≥2 = tool failure (a broken tool is not allowed to look like a clean pass). * **`relock`** — regenerates and delivers the file. A GitHub App cannot write under `.github/workflows/` at all (`permissions:` has no `workflows` key; the push is refused outright), so delivery is: push with `ACTIONS_LOCK_TOKEN` if that PAT is configured, otherwise publish the regenerated file as an artefact **and in full as a pull-request comment** so it can be applied by hand. ## Acceptance criteria, one by one | criterion | status | | --- | --- | | `Cross-Platform Build & Test` and `ABI Contract` start on a PR and on `main`, no `startup_failure`; each required context is a real check run | ✅ both `success` on the PR head | | required-context set is SET-EQUAL to what an actual PR head produces | ✅ all 5 required contexts report — `Linux`, `Idris2 model type-checks`, `Zig ↔ Idris tables in sync`, `AffineScript ↔ Zig FFI symbols in sync`, `scan / gitleaks` — all `success` | | `container/deploy.k9.ncl` carries a pedigree; `Validate K9 contracts` green | ✅ | | `SonarCloud Code Analysis` green on `main`, or removed with a stated reason | ✅ green on this PR head; the five vulnerabilities that make `main` red are removed by this PR's SHA-pinning and drop out on `main`'s next analysis | | `Governance` no longer `startup_failure` on `main` |⚠️ **blocked upstream** — see below | | `Mirror to Git Forges` no longer `startup_failure` on `main` |⚠️ **blocked upstream** — same cause | | `GitHub Pages` no longer `startup_failure` on `main` | ✅ `haskell-actions/setup` removed; it only triggers on push to `main`, so it cannot be exercised from a branch, but the rejected action is gone and the lockfile now validates | ## What is still blocked, and why `Governance` and `Mirror to Git Forges` are thin wrappers around `hyperpolymath/standards` reusable workflows, and the refused actions live **inside those reusable workflows**: ``` Governance editorconfig-checker/action-editorconfig-checker@840e866d Mirror to Git Forges webfactory/ssh-agent@e8387483, dtolnay/rust-toolchain@6c977a6c ``` Both have been there since those reusable workflows were created, so there is no earlier clean commit to re-pin to. The fix belongs upstream, and it is written and verified: **hyperpolymath/standards#1147** carries the complete patch (EditorConfig via pinned `go install` + Go checksum database; ssh-agent via `ssh-agent`/`ssh-add` with no third-party code; Rust toolchain via the runner's own stable Rust), validated with standards' own `validate-actions-lock.sh` at 24 refs / 23 keys / 0 errors. It is filed as an issue rather than a PR because the credential in this sandbox is a GitHub App installation without `contents: write` on `standards` — `git push` returns `Permission to hyperpolymath/standards.git denied to hyperpolymath` and `POST /git/refs` returns `Resource not accessible by integration`. The same patch is in the workspace as `standards-fix.patch` for anyone who can push it. --------- Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the actions group with 14 updates:
4.1.17.0.12.7.52.12.14.2.06.1.05.0.06.0.03.0.15.0.04.0.55.0.14.32.64.38.21.20.41.24.14.6.27.0.18.0.09.0.00.2.00.3.04.1.88.0.12.5.03.0.32.4.04.2.2Updates
actions/checkoutfrom 4.1.1 to 7.0.1Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
haskell-actions/setupfrom 2.7.5 to 2.12.1Release notes
Sourced from haskell-actions/setup's releases.
... (truncated)
Commits
0f8e8c9Add Cabal 3.18.1.0 and Stack 3.11.16037f33fix: parseYAMLBoolean for enable-stack/stack-no-global/stack-setup-ghc/disabl...d07e232fix: bump bundled ghcup from 0.1.50.2 to 0.2.6.25873697Bump actions/setup-node from 6 to 7482af4fBump actions/checkout from 6 to 7cd0d9bdGHC: try ghcup first, choco only as fallback4568e64Bump softprops/action-gh-release from 2 to 3de26526Add GHC 9.12.4 and Stack 3.9.3f9150cbAdd Stack 3.9.1dc63c94Remove GHCup vanilla channel from defaultsUpdates
actions/cachefrom 4.2.0 to 6.1.0Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesUpdates
actions/configure-pagesfrom 5.0.0 to 6.0.0Release notes
Sourced from actions/configure-pages's releases.
Commits
45bfe01Merge pull request #186 from salmanmkc/node24d8770c2Update Node version from 20 to 24 in action.ymlcb8a1a3upgrade to node 24d560657Merge pull request #165 from actions/Jcambass-patch-135e0ac4Upgrade IA Publish1dfbcbfMerge pull request #163 from actions/Jcambass-patch-12f4f988Add workflow file for publishing releases to immutable action package0d7570cMerge pull request #162 from actions/pin-draft-release-verssion3ea1966pin draft release versionaabcbc4Merge pull request #160 from actions/dependabot/npm_and_yarn/espree-10.1.0Updates
actions/upload-pages-artifactfrom 3.0.1 to 5.0.0Release notes
Sourced from actions/upload-pages-artifact's releases.
Commits
fc324d3Merge pull request #139 from Tom-van-Woudenberg/patch-1fe9d4b7Merge branch 'main' into patch-10ca1617Merge pull request #137 from jonchurch/include-hidden-files57f0e84Update action.yml4a90348v7 --> hash56f665aUpdate upload-artifact action to version 7f7615f5Addinclude-hidden-filesinput7b1f4a7Merge pull request #127 from heavymachinery/pin-sha4cc19c7Pinactions/upload-artifactto SHA2d163beMerge pull request #107 from KittyChiu/mainUpdates
actions/deploy-pagesfrom 4.0.5 to 5.0.1Release notes
Sourced from actions/deploy-pages's releases.
Commits
368f825Merge pull request #444 from actions/yoannchaudet-deployment-polling-backoff7e97763Validate deployment polling intervals0143e11Add backoff and jitter to deployment polling5e98f10Merge pull request #440 from actions/user/adwitiya8b0625aImprove deployment request test coveragecd2ce8fMerge pull request #404 from salmanmkc/node24bbe2a95Update Node.js version to 24.x854d7aaMerge pull request #374 from actions/Jcambass-patch-1306bb81Add workflow file for publishing releases to immutable action packageb742728Merge pull request #360 from actions/dependabot/npm_and_yarn/npm_and_yarn-513...Updates
github/codeql-actionfrom 4.32.6 to 4.38.2Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
erlef/setup-beamfrom 1.20.4 to 1.24.1Release notes
Sourced from erlef/setup-beam's releases.