ci: guard vendored glib provenance (#71) + codeql init+analyze 4.38.1 - #155
Merged
Merged
Conversation
Dependabot split the bump across #151 and #154; each alone fails every analyze job because init and analyze must run the same action version (same fix as #138). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
Adds a vendor-provenance workflow that downloads glib 0.18.5 from crates.io, checks it against the checksum pinned in PROVENANCE.md, and diffs it against vendor/glib-0.18.5-patched/. Any difference other than the deltas pinned (with SHA-256) in PROVENANCE.md's provenance block fails, so editing a delta requires updating PROVENANCE.md too. The first run found an undocumented fourth delta: the .cargo-ok registry extraction marker copied along with the source. It is not crate content, so it is removed rather than documented. Closes #71 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
This was referenced Sep 24, 2026
This PR touches vendor/glib-0.18.5-patched/, which triggers cargo audit, and main still carries rustls 0.23.43. Taking #152's lockfile verbatim keeps audit green here; it no-ops once #152 merges. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
Member
Author
|
This PR changes To keep this PR green, I copied #152's Generated by Claude Code |
tonibergholm-codento
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two CI changes from a triage sweep of open PRs and issues:
1. Vendored glib provenance check (closes #71)
vendor-provenanceworkflow runs.github/scripts/verify_glib_provenance.py. The script downloadsglib-0.18.5.cratefrom crates.io, checks it against the checksum pinned inPROVENANCE.md, and diffs the extracted source againstvendor/glib-0.18.5-patched/.PROVENANCE.mdgets a machine-readableprovenanceblock that pins the crate checksum and a SHA-256 for each delta file (src/variant_iter.rs,src/lib.rs). CI fails on:PROVENANCE.md;.cargo-okregistry-extraction marker ({"v":1}) was copied in with the source. It isn't crate content and cargo ignores it for path deps, so this PR removes it rather than documenting it.2.
github/codeql-actioninit+analyze → 4.38.1 togetherDependabot split this bump into two PRs, #151 and #154. Merged alone, each one fails all three
analyzejobs because init and analyze have to run the same version. This is the same situation as #138. This PR supersedes both.Test plan
README.md), added file, removed file, and a corrupt crate (checksum mismatch).cargo metadatastill resolves after removing.cargo-ok.vendor-provenanceand CodeQLanalyzejobs are green on this PR.🤖 Generated with Claude Code
https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
Generated by Claude Code