diff --git a/.github/workflows/abi-contract.yml b/.github/workflows/abi-contract.yml index 09430e1..5c65495 100644 --- a/.github/workflows/abi-contract.yml +++ b/.github/workflows/abi-contract.yml @@ -32,7 +32,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@v4.2.2 + uses: actions/checkout@v7.0.1 - name: Install Zig 0.15.2 # Pinned + sha256-verified tarball; no third-party action (#103). @@ -75,7 +75,7 @@ jobs: image: ghcr.io/stefan-hoeck/idris2-pack@sha256:370e2ab066251cf278ac6928d9201ade0aca70c4e7ee1cc434d25bcea1669b29 steps: - name: Checkout - uses: actions/checkout@v4.2.2 + uses: actions/checkout@v7.0.1 - name: Install Zig download prerequisites in the Idris image run: | @@ -95,7 +95,7 @@ jobs: timeout-minutes: 5 steps: - name: Checkout - uses: actions/checkout@v4.2.2 + uses: actions/checkout@v7.0.1 # Symbol-level contract only (pure grep/comm — no toolchain): every # extern in src/ui/tea/gsa_ffi.affine must be a real Zig export, and diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 44dc4c4..c3ad3dc 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -18,7 +18,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout - uses: actions/checkout@v4.1.7 + uses: actions/checkout@v7.0.1 - name: Trigger BoJ Server (Casket/ssg-mcp) env: BOJ_URL: ${{ secrets.BOJ_SERVER_URL || vars.BOJ_SERVER_URL }} diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index e35ce7d..8746d9f 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -23,22 +23,22 @@ jobs: timeout-minutes: 30 steps: - name: Checkout - uses: actions/checkout@v4.1.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@v4.1.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@v2.7.5 + uses: haskell-actions/setup@v2.12.1 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@v4.3.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -100,10 +100,10 @@ jobs: touch ../_site/.nojekyll - name: Setup Pages - uses: actions/configure-pages@v5.0.0 + uses: actions/configure-pages@v6.0.0 - name: Upload artifact - uses: actions/upload-pages-artifact@v3.0.1 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' @@ -117,4 +117,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@v4.0.5 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index e6d27cf..3e3d82f 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -42,15 +42,15 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@v4.34.0 + uses: github/codeql-action/init@v4.38.2 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4.34.0 + uses: github/codeql-action/analyze@v4.38.2 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/cross-platform.yml b/.github/workflows/cross-platform.yml index 40db85c..9220ca3 100644 --- a/.github/workflows/cross-platform.yml +++ b/.github/workflows/cross-platform.yml @@ -33,14 +33,14 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4.2.2 + uses: actions/checkout@v7.0.1 - name: Install Zig 0.15.2 # Pinned + sha256-verified tarball; no third-party action (#103). run: bash scripts/install-zig.sh - name: Cache Zig - uses: actions/cache@v4.2.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cache/zig diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 94f3a92..bda69e5 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -28,7 +28,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4.3.1 + uses: actions/checkout@v7.0.1 - name: Check for manifest files (.a2ml/.deed) id: detect @@ -73,7 +73,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4.3.1 + uses: actions/checkout@v7.0.1 - name: Check for K9 files id: detect @@ -123,7 +123,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4.3.1 + uses: actions/checkout@v7.0.1 - name: Scan for invisible characters id: lint @@ -188,7 +188,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4.3.1 + uses: actions/checkout@v7.0.1 - name: Check for Groove manifest id: groove @@ -247,7 +247,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4.3.1 + uses: actions/checkout@v7.0.1 - name: Check and validate eclexiaiser manifest id: eclex @@ -313,7 +313,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4.3.1 + uses: actions/checkout@v7.0.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 66c8471..eaad1cb 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -49,12 +49,12 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 # Full history for better pattern analysis - name: Setup Elixir for Hypatia scanner - uses: erlef/setup-beam@v1.24.0 + uses: erlef/setup-beam@v1.24.1 with: elixir-version: '1.18' otp-version: '27' @@ -108,7 +108,7 @@ jobs: echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY - name: Upload findings artifact - uses: actions/upload-artifact@v4.6.2 + uses: actions/upload-artifact@v7.0.1 with: name: hypatia-findings path: hypatia-findings.json @@ -244,7 +244,7 @@ jobs: always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.fork != true) - uses: github/codeql-action/upload-sarif@v4.32.6 + uses: github/codeql-action/upload-sarif@v4.38.2 with: sarif_file: hypatia.sarif # Distinct category so Hypatia results coexist with CodeQL's @@ -384,7 +384,7 @@ jobs: # the pull-requests: write permission above: a token/API hiccup or # a fork PR (read-only token) skips the comment, not the check. continue-on-error: true - uses: actions/github-script@v8.0.0 + uses: actions/github-script@v9.0.0 with: script: | const fs = require('fs'); diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 676f498..438d01a 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -40,7 +40,7 @@ jobs: timeout-minutes: 5 steps: - name: Send push notification email - uses: hyperpolymath/smtp-notify-action@v0.2.0 + uses: hyperpolymath/smtp-notify-action@v0.3.0 with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 65fa27f..cef733c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -24,7 +24,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@v6.0.2 + - uses: actions/checkout@v7.0.1 - name: Build run: | @@ -38,7 +38,7 @@ jobs: cp src/interface/ffi/zig-out/lib/libgsa.so release-artifacts/ 2>/dev/null || true tar -czf release-artifacts/gsa-linux-x86_64.tar.gz -C release-artifacts gsa - - uses: actions/upload-artifact@v4.6.2 + - uses: actions/upload-artifact@v7.0.1 with: name: release-artifacts path: release-artifacts/ @@ -54,7 +54,7 @@ jobs: changelog: ${{ steps.cliff.outputs.content }} version: ${{ steps.version.outputs.version }} steps: - - uses: actions/checkout@v6.0.2 + - uses: actions/checkout@v7.0.1 with: fetch-depth: 0 @@ -84,7 +84,7 @@ jobs: git cliff --output CHANGELOG.md - name: Upload updated CHANGELOG.md - uses: actions/upload-artifact@v4.6.2 + uses: actions/upload-artifact@v7.0.1 with: name: changelog path: CHANGELOG.md @@ -100,15 +100,15 @@ jobs: id-token: write attestations: write steps: - - uses: actions/checkout@v6.0.2 + - uses: actions/checkout@v7.0.1 - - uses: actions/download-artifact@v4.3.0 + - uses: actions/download-artifact@v8.0.1 with: name: release-artifacts path: artifacts/ - name: Create GitHub Release - uses: softprops/action-gh-release@v2.5.0 + uses: softprops/action-gh-release@v3.0.3 with: body: ${{ needs.changelog.outputs.changelog }} draft: false @@ -120,7 +120,7 @@ jobs: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Attest build provenance - uses: actions/attest-build-provenance@v2.4.0 + uses: actions/attest-build-provenance@v4.2.2 with: subject-path: | artifacts/gsa-linux-x86_64.tar.gz diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml index 80393d5..3255b45 100644 --- a/.github/workflows/static-analysis-gate.yml +++ b/.github/workflows/static-analysis-gate.yml @@ -25,7 +25,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 @@ -128,7 +128,7 @@ jobs: echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload panic-attack findings - uses: actions/upload-artifact@v4.6.2 + uses: actions/upload-artifact@v7.0.1 with: name: panic-attack-findings path: panic-attack-findings.json @@ -150,14 +150,14 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Setup Elixir for Hypatia scanner id: beam continue-on-error: true - uses: erlef/setup-beam@v1.20.4 + uses: erlef/setup-beam@v1.24.1 with: elixir-version: '1.19.4' otp-version: '28.3' @@ -263,7 +263,7 @@ jobs: echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload hypatia findings - uses: actions/upload-artifact@v4.6.2 + uses: actions/upload-artifact@v7.0.1 with: name: hypatia-findings path: hypatia-findings.json @@ -285,7 +285,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 @@ -352,7 +352,7 @@ jobs: echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload bridge report - uses: actions/upload-artifact@v4.6.2 + uses: actions/upload-artifact@v7.0.1 with: name: bridge-report path: bridge-report.json @@ -377,19 +377,19 @@ jobs: steps: - name: Download panic-attack findings - uses: actions/download-artifact@v4.1.8 + uses: actions/download-artifact@v8.0.1 with: name: panic-attack-findings path: findings/ - name: Download hypatia findings - uses: actions/download-artifact@v4.1.8 + uses: actions/download-artifact@v8.0.1 with: name: hypatia-findings path: findings/ - name: Download bridge report - uses: actions/download-artifact@v4.1.8 + uses: actions/download-artifact@v8.0.1 with: name: bridge-report path: findings/ @@ -451,7 +451,7 @@ jobs: echo "low=$LOW" >> "$GITHUB_OUTPUT" - name: Upload unified findings (fleet scanner picks these up) - uses: actions/upload-artifact@v4.6.2 + uses: actions/upload-artifact@v7.0.1 with: name: unified-findings path: findings/unified-findings.json