Skip to content

ci: guard vendored glib provenance (#71) + codeql init+analyze 4.38.1 - #155

Merged
tonibergholm merged 4 commits into
mainfrom
claude/vibrant-fermi-hu1h21
Sep 24, 2026
Merged

tonibergholm merged 4 commits into
mainfrom
claude/vibrant-fermi-hu1h21

Conversation

@tonibergholm

Copy link
Copy Markdown
Member

Summary

Two CI changes from a triage sweep of open PRs and issues:

1. Vendored glib provenance check (closes #71)

  • New vendor-provenance workflow runs .github/scripts/verify_glib_provenance.py. The script downloads glib-0.18.5.crate from crates.io, checks it against the checksum pinned in PROVENANCE.md, and diffs the extracted source against vendor/glib-0.18.5-patched/.
  • PROVENANCE.md gets a machine-readable provenance block that pins the crate checksum and a SHA-256 for each delta file (src/variant_iter.rs, src/lib.rs). CI fails on:
    • any undocumented change, addition, or removal;
    • an edit to a delta file without a matching hash update in PROVENANCE.md;
    • a documented delta that no longer differs from upstream;
    • a crate checksum mismatch.
  • The first run found an undocumented fourth delta: the .cargo-ok registry-extraction marker ({"v":1}) was copied in with the source. It isn't crate content and cargo ignores it for path deps, so this PR removes it rather than documenting it.

2. github/codeql-action init+analyze → 4.38.1 together

Dependabot split this bump into two PRs, #151 and #154. Merged alone, each one fails all three analyze jobs because init and analyze have to run the same version. This is the same situation as #138. This PR supersedes both.

Test plan

  • The script passes against the live crates.io download.
  • I tried each failure mode locally and each one exits non-zero with a clear message: edited delta, edited non-delta (README.md), added file, removed file, and a corrupt crate (checksum mismatch).
  • cargo metadata still resolves after removing .cargo-ok.
  • CI: the vendor-provenance and CodeQL analyze jobs are green on this PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99


Generated by Claude Code

Dependabot split the bump across #151 and #154; each alone fails every
analyze job because init and analyze must run the same action version
(same fix as #138).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
Adds a vendor-provenance workflow that downloads glib 0.18.5 from
crates.io, checks it against the checksum pinned in PROVENANCE.md, and
diffs it against vendor/glib-0.18.5-patched/. Any difference other than
the deltas pinned (with SHA-256) in PROVENANCE.md's provenance block
fails, so editing a delta requires updating PROVENANCE.md too.

The first run found an undocumented fourth delta: the .cargo-ok registry
extraction marker copied along with the source. It is not crate content,
so it is removed rather than documented.

Closes #71

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99
This PR touches vendor/glib-0.18.5-patched/, which triggers cargo audit,
and main still carries rustls 0.23.43. Taking #152's lockfile verbatim
keeps audit green here; it no-ops once #152 merges.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013z24CKdETNZRqL7CKMur99

Copy link
Copy Markdown
Member Author

This PR changes vendor/glib-0.18.5-patched/, so cargo audit (RustSec advisories) runs on it. That check fails on main too, because main still has rustls 0.23.43 (RUSTSEC-2026-0285). The failure isn't caused by this PR.

To keep this PR green, I copied #152's Cargo.lock over unchanged in fac28c3; it's the only file #152 changes. Once #152 merges, that commit changes nothing, so the two PRs can merge in either order.


Generated by Claude Code

@tonibergholm
tonibergholm merged commit 10c0e3d into main Sep 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: guard vendored glib provenance against drift

3 participants