Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
138 changes: 138 additions & 0 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
# This file is machine-generated by `gh actions-lock`.
# Do not edit by hand; run `gh actions-lock` to update.
# Docs: https://gh.io/actions-lockfile
version: 'v0.0.2'
workflows:
'.github/workflows/governance.yml': []
'.github/workflows/secret-scanner.yml': []
'.github/workflows/casket-pages.yml':
- 'actions/cache@v4.3.0'
- 'actions/checkout@v4.1.1'
- 'actions/configure-pages@v5.0.0'
- 'actions/deploy-pages@v4.0.5'
- 'actions/upload-pages-artifact@v3.0.1'
- 'haskell-actions/setup@v2.7.5'
'.github/workflows/codeql.yml':
- 'actions/checkout@v6.0.1'
- 'github/codeql-action@v4.31.10'
'.github/workflows/deploy-site.yml':
- 'actions/checkout@v4.1.1'
- 'actions/configure-pages@v5.0.0'
- 'actions/deploy-pages@v4.0.5'
- 'actions/upload-pages-artifact@v3.0.1'
'.github/workflows/hypatia-scan.yml':
- 'actions/checkout@v4.1.1'
- 'actions/github-script@v7.0.1'
- 'actions/upload-artifact@v4.6.2'
- 'erlef/setup-beam@v1.17.5'
'.github/workflows/push-email-notify.yml':
- 'dawidd6/action-send-mail@v3.12.0'
'.github/workflows/release.yml':
- 'actions/checkout@v4.1.1'
- 'docker/build-push-action@v5.1.0'
- 'docker/login-action@v3.0.0'
- 'docker/metadata-action@v5.5.1'
- 'docker/setup-buildx-action@v3.0.0'
- 'softprops/action-gh-release@v2.2.2'
'.github/workflows/scorecard.yml':
- 'actions/checkout@v6.0.1'
- 'github/codeql-action@v4.31.10'
- 'ossf/scorecard-action@v2.4.3'
dependencies:
'actions/cache@v4.3.0':
ref: 'v4.3.0'
commit: 'sha1-0057852bfaa89a56745cba8c7296529d2fc39830'
owner_id: 44036562
repo_id: 215566462
'actions/checkout@v4.1.1':
ref: 'v4.1.1'
commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11'
owner_id: 44036562
repo_id: 197814629
'actions/checkout@v6.0.1':
ref: 'v6.0.1'
commit: 'sha1-8e8c483db84b4bee98b60c0593521ed34d9990e8'
owner_id: 44036562
repo_id: 197814629
'actions/configure-pages@v5.0.0':
ref: 'v5.0.0'
commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b'
owner_id: 44036562
repo_id: 513659658
'actions/deploy-pages@v4.0.5':
ref: 'v4.0.5'
commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e'
owner_id: 44036562
repo_id: 438112499
'actions/github-script@v7.0.1':
ref: 'v7.0.1'
commit: 'sha1-60a0d83039c74a4aee543508d2ffcb1c3799cdea'
owner_id: 44036562
repo_id: 205262760
'actions/upload-artifact@v4':
ref: 'v4'
commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02'
owner_id: 44036562
repo_id: 192625955
'actions/upload-artifact@v4.6.2':
ref: 'v4.6.2'
commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02'
owner_id: 44036562
repo_id: 192625955
'actions/upload-pages-artifact@v3.0.1':
ref: 'v3.0.1'
commit: 'sha1-56afc609e74202658d3ffba0e8f6dda462b719fa'
owner_id: 44036562
repo_id: 496012378
uses:
- 'actions/upload-artifact@v4'
'dawidd6/action-send-mail@v3.12.0':
ref: 'v3.12.0'
commit: 'sha1-6e502825a508b867ab2954ad6343b68787624c01'
owner_id: 9713907
repo_id: 222439721
'docker/build-push-action@v5.1.0':
ref: 'v5.1.0'
commit: 'sha1-4a13e500e55cf31b7a5d59a38ab2040ab0f42f56'
owner_id: 5429470
repo_id: 241092383
'docker/login-action@v3.0.0':
ref: 'v3.0.0'
commit: 'sha1-343f7c4344506bcbf9b4de18042ae17996df046d'
owner_id: 5429470
repo_id: 287743349
'docker/metadata-action@v5.5.1':
ref: 'v5.5.1'
commit: 'sha1-8e5442c4ef9f78752691e2d8f8d19755c6f78e81'
owner_id: 5429470
repo_id: 306769011
'docker/setup-buildx-action@v3.0.0':
ref: 'v3.0.0'
commit: 'sha1-f95db51fddba0c2d1ec667646a06c2ce06100226'
owner_id: 5429470
repo_id: 288485773
'erlef/setup-beam@v1.17.5':
ref: 'v1.17.5'
commit: 'sha1-2f0cc07b4b9bea248ae098aba9e1a8a1de5ec24c'
owner_id: 47606891
repo_id: 331103973
'github/codeql-action@v4.31.10':
ref: 'v4.31.10'
commit: 'sha1-cdefb33c0f6224e58673d9004f47f7cb3e328b89'
owner_id: 9919
repo_id: 259445878
'haskell-actions/setup@v2.7.5':
ref: 'v2.7.5'
commit: 'sha1-ec49483bfc012387b227434aba94f59a6ecd0900'
owner_id: 75048950
repo_id: 623796603
'ossf/scorecard-action@v2.4.3':
ref: 'v2.4.3'
commit: 'sha1-4eaacf0543bb3f2c246792bd56e8cdeffafb205a'
owner_id: 67707773
repo_id: 421101922
'softprops/action-gh-release@v2.2.2':
ref: 'v2.2.2'
commit: 'sha1-da05d552573ad5aba039eaac05058a918a7bf631'
owner_id: 2242
repo_id: 204253808
15 changes: 8 additions & 7 deletions .github/workflows/casket-pages.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: GitHub Pages

on:
Expand All @@ -20,22 +21,22 @@
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1

- name: Checkout casket-ssg
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1
with:
repository: hyperpolymath/casket-ssg
path: .casket-ssg

- name: Setup GHCup
uses: haskell-actions/setup@ec49483bfc012387b227434aba94f59a6ecd0900 # v2
uses: haskell-actions/setup@v2.7.5

Check failure on line 33 in .github/workflows/casket-pages.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcCF18PxM1woCW5W&open=AaBBYcCF18PxM1woCW5W&pullRequest=18
with:
ghc-version: '9.8.2'
cabal-version: '3.10'

- name: Cache Cabal
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
uses: actions/cache@v4.3.0
with:
path: |
~/.cabal/packages
Expand Down Expand Up @@ -79,10 +80,10 @@
cd .casket-ssg && cabal run casket-ssg -- build ../site ../_site

- name: Setup Pages
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5
uses: actions/configure-pages@v5.0.0

- name: Upload artifact
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3
uses: actions/upload-pages-artifact@v3.0.1
with:
path: '_site'

Expand All @@ -95,4 +96,4 @@
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4
uses: actions/deploy-pages@v4.0.5
7 changes: 4 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: CodeQL Security Analysis

on:
Expand Down Expand Up @@ -26,15 +27,15 @@ jobs:

steps:
- name: Checkout
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
uses: actions/checkout@v6.0.1

- name: Initialize CodeQL
uses: github/codeql-action/init@cdefb33c0f6224e58673d9004f47f7cb3e328b89 # v3.28.1
uses: github/codeql-action/init@v4.31.10
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@cdefb33c0f6224e58673d9004f47f7cb3e328b89 # v3.28.1
uses: github/codeql-action/analyze@v4.31.10
with:
category: "/language:${{ matrix.language }}"
9 changes: 5 additions & 4 deletions .github/workflows/deploy-site.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Deploy Landing Page

on:
Expand All @@ -23,7 +24,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1

- name: Convert docs to HTML
run: |
Expand Down Expand Up @@ -52,13 +53,13 @@ jobs:
cp examples/*.json docs/site/examples/

- name: Setup Pages
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5
uses: actions/configure-pages@v5.0.0

- name: Upload artifact
uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3
uses: actions/upload-pages-artifact@v3.0.1
with:
path: 'docs/site'

- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4
uses: actions/deploy-pages@v4.0.5
2 changes: 2 additions & 0 deletions .github/workflows/governance.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# governance.yml — single wrapper calling the shared estate governance bundle
# in hyperpolymath/standards instead of carrying per-repo copies.
#
Expand All @@ -19,6 +20,7 @@ on:
workflow_dispatch:

permissions:
actions: read
contents: read

jobs:
Expand Down
9 changes: 5 additions & 4 deletions .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Hypatia Neurosymbolic CI/CD Security Scan
name: Hypatia Security Scan

Expand All @@ -20,12 +21,12 @@

steps:
- name: Checkout repository
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1
with:
fetch-depth: 0 # Full history for better pattern analysis

- name: Setup Elixir for Hypatia scanner
uses: erlef/setup-beam@2f0cc07b4b9bea248ae098aba9e1a8a1de5ec24c # v1.18.2
uses: erlef/setup-beam@v1.17.5

Check failure on line 29 in .github/workflows/hypatia-scan.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcFF18PxM1woCW5Y&open=AaBBYcFF18PxM1woCW5Y&pullRequest=18
with:
elixir-version: '1.19.4'
otp-version: '28.3'
Expand Down Expand Up @@ -75,7 +76,7 @@
echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY

- name: Upload findings artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@v4.6.2
with:
name: hypatia-findings
path: hypatia-findings.json
Expand Down Expand Up @@ -146,7 +147,7 @@

- name: Comment on PR with findings
if: github.event_name == 'pull_request' && steps.scan.outputs.findings_count > 0
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7
uses: actions/github-script@v7.0.1
with:
script: |
const fs = require('fs');
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/push-email-notify.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Dormant push-email notification. ARMED by setting the repo variable
# PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled;
# sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by
Expand All @@ -15,7 +16,7 @@
runs-on: ubuntu-latest
steps:
- name: Send push notification email
uses: dawidd6/action-send-mail@6e502825a508b867ab2954ad6343b68787624c01 # pinned
uses: dawidd6/action-send-mail@v3.12.0

Check failure on line 19 in .github/workflows/push-email-notify.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcEM18PxM1woCW5X&open=AaBBYcEM18PxM1woCW5X&pullRequest=18
with:
server_address: ${{ secrets.SMTP_HOST }}
server_port: ${{ secrets.SMTP_PORT }}
Expand Down
13 changes: 7 additions & 6 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Release

on:
Expand All @@ -16,21 +17,21 @@
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@f95db51fddba0c2d1ec667646a06c2ce06100226 # v3
uses: docker/setup-buildx-action@v3.0.0

Check failure on line 23 in .github/workflows/release.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcF318PxM1woCW5a&open=AaBBYcF318PxM1woCW5a&pullRequest=18

- name: Login to GitHub Container Registry
uses: docker/login-action@343f7c4344506bcbf9b4de18042ae17996df046d # v3
uses: docker/login-action@v3.0.0

Check failure on line 26 in .github/workflows/release.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcF318PxM1woCW5b&open=AaBBYcF318PxM1woCW5b&pullRequest=18
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Extract metadata
id: meta
uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5
uses: docker/metadata-action@v5.5.1

Check failure on line 34 in .github/workflows/release.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcF318PxM1woCW5c&open=AaBBYcF318PxM1woCW5c&pullRequest=18
with:
images: ghcr.io/${{ github.repository }}
tags: |
Expand All @@ -41,7 +42,7 @@
type=sha

- name: Build and push Docker image
uses: docker/build-push-action@4a13e500e55cf31b7a5d59a38ab2040ab0f42f56 # v5
uses: docker/build-push-action@v5.1.0

Check failure on line 45 in .github/workflows/release.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcF318PxM1woCW5d&open=AaBBYcF318PxM1woCW5d&pullRequest=18
with:
context: .
push: true
Expand All @@ -52,7 +53,7 @@
platforms: linux/amd64,linux/arm64

- name: Create GitHub Release
uses: softprops/action-gh-release@da05d552573ad5aba039eaac05058a918a7bf631 # v2
uses: softprops/action-gh-release@v2.2.2

Check failure on line 56 in .github/workflows/release.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcF318PxM1woCW5e&open=AaBBYcF318PxM1woCW5e&pullRequest=18
if: startsWith(github.ref, 'refs/tags/')
with:
generate_release_notes: true
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: OSSF Scorecard
on:
schedule:
Expand All @@ -14,17 +15,17 @@
security-events: write
id-token: write
steps:
- uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
- uses: actions/checkout@v6.0.1
with:
persist-credentials: false

- name: Run Scorecard
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.3.1
uses: ossf/scorecard-action@v2.4.3

Check failure on line 23 in .github/workflows/scorecard.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_glyphbase&issues=AaBBYcFk18PxM1woCW5Z&open=AaBBYcFk18PxM1woCW5Z&pullRequest=18
with:
results_file: results.sarif
results_format: sarif

- name: Upload results
uses: github/codeql-action/upload-sarif@cdefb33c0f6224e58673d9004f47f7cb3e328b89 # v3.31.8
uses: github/codeql-action/upload-sarif@v4.31.10
with:
sarif_file: results.sarif
Loading
Loading