-
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(ci): unbreak the workflow YAML, then add a COMPLETE actions.lock #83
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,102 @@ | ||
| # This file is machine-generated by `gh actions-lock`. | ||
| # Do not edit by hand; run `gh actions-lock` to update. | ||
| # Docs: https://gh.io/actions-lockfile | ||
| version: 'v0.0.2' | ||
| workflows: | ||
| '.github/workflows/governance.yml': [] | ||
| '.github/workflows/hypatia-scan.yml': [] | ||
| '.github/workflows/mirror.yml': [] | ||
| '.github/workflows/scorecard.yml': [] | ||
| '.github/workflows/secret-scanner.yml': [] | ||
| '.github/workflows/boj-build.yml': | ||
| - 'actions/checkout@v7.0.1' | ||
| '.github/workflows/casket-pages.yml': | ||
| - 'actions/cache@v6.1.0' | ||
| - 'actions/checkout@v7.0.1' | ||
| - 'actions/configure-pages@v6.0.0' | ||
| - 'actions/deploy-pages@v5.0.0' | ||
| - 'actions/upload-pages-artifact@v5.0.0' | ||
| - 'haskell-actions/setup@v2.11.0' | ||
| '.github/workflows/codeql.yml': | ||
| - 'actions/checkout@v7.0.1' | ||
| - 'github/codeql-action@v4.37.3' | ||
| '.github/workflows/dogfood-gate.yml': | ||
| - 'actions/checkout@v7.0.1' | ||
| '.github/workflows/generator-generic-ossf-slsa3-publish.yml': | ||
| - 'actions/checkout@v7.0.1' | ||
| '.github/workflows/instant-sync.yml': | ||
| - 'peter-evans/repository-dispatch@v4.0.1' | ||
| '.github/workflows/main-estate-audit.yml': | ||
| - 'actions/checkout@v4.4.0' | ||
| - 'hyperpolymath/cicd-suite@main' | ||
| '.github/workflows/pages.yml': | ||
| - 'actions/checkout@v7.0.1' | ||
| - 'actions/deploy-pages@v5.0.0' | ||
| - 'actions/upload-pages-artifact@v5.0.0' | ||
| '.github/workflows/push-email-notify.yml': | ||
| - 'dawidd6/action-send-mail@v3.12.0' | ||
| '.github/workflows/workflow-linter.yml': | ||
| - 'actions/checkout@v7.0.1' | ||
| dependencies: | ||
| 'actions/cache@v6.1.0': | ||
| ref: 'v6.1.0' | ||
| commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' | ||
| owner_id: 44036562 | ||
| repo_id: 215566462 | ||
| 'actions/checkout@v4.4.0': | ||
| ref: 'v4.4.0' | ||
| commit: 'sha1-11d5960a326750d5838078e36cf38b85af677262' | ||
| owner_id: 44036562 | ||
| repo_id: 197814629 | ||
| 'actions/checkout@v7.0.1': | ||
| ref: 'v7.0.1' | ||
| commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' | ||
| owner_id: 44036562 | ||
| repo_id: 197814629 | ||
| 'actions/configure-pages@v6.0.0': | ||
| ref: 'v6.0.0' | ||
| commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' | ||
| owner_id: 44036562 | ||
| repo_id: 513659658 | ||
| 'actions/deploy-pages@v5.0.0': | ||
| ref: 'v5.0.0' | ||
| commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' | ||
| owner_id: 44036562 | ||
| repo_id: 438112499 | ||
| 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f': | ||
| ref: 'v7.0.0' | ||
| commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' | ||
| owner_id: 44036562 | ||
| repo_id: 192625955 | ||
| 'actions/upload-pages-artifact@v5.0.0': | ||
| ref: 'v5.0.0' | ||
| commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9' | ||
| owner_id: 44036562 | ||
| repo_id: 496012378 | ||
| uses: | ||
| - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' | ||
| 'dawidd6/action-send-mail@v3.12.0': | ||
| ref: 'v3.12.0' | ||
| commit: 'sha1-12335b969ae3fb71bee5f2c6b829744261aec34c' | ||
| owner_id: 9713907 | ||
| repo_id: 222439721 | ||
| 'github/codeql-action@v4.37.3': | ||
| ref: 'v4.37.3' | ||
| commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81' | ||
| owner_id: 9919 | ||
| repo_id: 259445878 | ||
| 'haskell-actions/setup@v2.11.0': | ||
| ref: 'v2.11.0' | ||
| commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553' | ||
| owner_id: 75048950 | ||
| repo_id: 623796603 | ||
| 'hyperpolymath/cicd-suite@main': | ||
| ref: 'main' | ||
| commit: 'sha1-a3cd79fba541444c619902330d0b618eb1612634' | ||
| owner_id: 6759885 | ||
| repo_id: 1326697643 | ||
| 'peter-evans/repository-dispatch@v4.0.1': | ||
| ref: 'v4.0.1' | ||
| commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' | ||
| owner_id: 18365890 | ||
| repo_id: 220359305 |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| name: GitHub Pages | ||
|
|
||
| on: | ||
|
|
@@ -21,22 +22,22 @@ | |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 | ||
| uses: actions/checkout@v7.0.1 | ||
|
|
||
| - name: Checkout casket-ssg | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 | ||
| uses: actions/checkout@v7.0.1 | ||
| with: | ||
| repository: hyperpolymath/casket-ssg | ||
| path: .casket-ssg | ||
|
|
||
| - name: Setup GHCup | ||
| uses: haskell-actions/setup@cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553 # v2 | ||
| uses: haskell-actions/setup@v2.11.0 | ||
|
Check failure on line 34 in .github/workflows/casket-pages.yml
|
||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 HIGH RISK To ensure a secure and reproducible build environment for your Haskell-based site, pin haskell-actions/setup to a full commit SHA. |
||
| with: | ||
| ghc-version: '9.8.2' | ||
| cabal-version: '3.10' | ||
|
|
||
| - name: Cache Cabal | ||
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | ||
| uses: actions/cache@v6.1.0 | ||
| with: | ||
| path: | | ||
| ~/.cabal/packages | ||
|
|
@@ -98,10 +99,10 @@ | |
| touch ../_site/.nojekyll | ||
|
|
||
| - name: Setup Pages | ||
| uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 | ||
| uses: actions/configure-pages@v6.0.0 | ||
|
|
||
| - name: Upload artifact | ||
| uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 | ||
| uses: actions/upload-pages-artifact@v5.0.0 | ||
| with: | ||
| path: '_site' | ||
|
|
||
|
|
@@ -114,4 +115,4 @@ | |
| steps: | ||
| - name: Deploy to GitHub Pages | ||
| id: deployment | ||
| uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 | ||
| uses: actions/deploy-pages@v5.0.0 | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| name: Governance | ||
|
|
||
| on: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # Instant Forge Sync - Triggers propagation to all forges on push/release | ||
| name: Instant Sync | ||
|
|
||
|
|
@@ -17,7 +18,7 @@ | |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Trigger Propagation | ||
| uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v3 | ||
| uses: peter-evans/repository-dispatch@v4.0.1 | ||
|
Check failure on line 21 in .github/workflows/instant-sync.yml
|
||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 HIGH RISK Pinning peter-evans/repository-dispatch to a SHA is necessary to protect the FARM_DISPATCH_TOKEN. Tags are mutable and do not guarantee that the code will not change in the future. |
||
| with: | ||
| token: ${{ secrets.FARM_DISPATCH_TOKEN }} | ||
| repository: hyperpolymath/.git-private-farm | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # Dormant push-email notification. ARMED by setting the repo variable | ||
| # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; | ||
| # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by | ||
|
|
@@ -16,7 +17,7 @@ | |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Send push notification email | ||
| uses: dawidd6/action-send-mail@12335b969ae3fb71bee5f2c6b829744261aec34c # pinned | ||
| uses: dawidd6/action-send-mail@v3.12.0 | ||
|
Check failure on line 20 in .github/workflows/push-email-notify.yml
|
||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 HIGH RISK This action handles your SMTP credentials and project data. Using a mutable version tag like v3.12.0 is insecure as it can be reassigned. Pinning to a full commit SHA ensures the code remains immutable. |
||
| with: | ||
| server_address: ${{ secrets.SMTP_HOST }} | ||
| server_port: ${{ secrets.SMTP_PORT }} | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| name: OSSF Scorecard | ||
|
|
||
| on: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| name: Secret Scanner | ||
|
|
||
| on: | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 HIGH RISK This change removes the SHA comments that the security linter uses to verify pinned actions. Since you are moving to an actions.lock strategy, the linter's 'Check pinned actions' step will now flag these as unpinned. You should update the linter logic to exempt files that contain the header '# This workflow is managed by gh actions-lock.' |
||
| # Prevention workflow - validates all workflows have proper security config | ||
| name: Workflow Security Linter | ||
|
|
||
|
|
@@ -10,14 +11,15 @@ on: | |
| paths: | ||
| - '.github/workflows/**' | ||
|
|
||
| permissions: read-all | ||
| permissions: | ||
| contents: read | ||
| actions: read | ||
|
|
||
| jobs: | ||
| lint-workflows: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 | ||
| - uses: actions/checkout@v7.0.1 | ||
|
|
||
| - name: Check SPDX headers | ||
| run: | | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 MEDIUM RISK
This update to a tag-pinned version without a trailing comment will trigger a failure in the 'Check pinned actions' step of this workflow, as the linter specifically looks for tags without comments to identify unpinned dependencies.