Skip to content

Bump webfactory/ssh-agent from 0.9.0 to 0.9.1 - #4

Merged
hyperpolymath merged 3 commits into
mainfrom
dependabot/github_actions/webfactory/ssh-agent-0.9.1
Dec 29, 2025
Merged

hyperpolymath merged 3 commits into
mainfrom
dependabot/github_actions/webfactory/ssh-agent-0.9.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Dec 29, 2025

Copy link
Copy Markdown
Contributor

Bumps webfactory/ssh-agent from 0.9.0 to 0.9.1.

Release notes

Sourced from webfactory/ssh-agent's releases.

v0.9.1

What's Changed

New Contributors

Full Changelog: webfactory/ssh-agent@v0.9.0...v0.9.1

Changelog

Sourced from webfactory/ssh-agent's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

v0.9.1 [2024-03-17]

Fixed

  • Fix path used to execute ssh-agent in cleanup.js to respect custom paths set by input (#235)

v0.9.0 [2024-02-06]

Changed

  • Update all versions of actions/checkout to v4 (#199)
  • Update to Node 20 (#201)

v0.8.0 [2023-03-24]

Changed

  • No longer writing GitHub's SSH host keys to known_hosts (#171)
  • Update to actions/checkout@v3 (#143)
  • Allow the user to override the commands for git, ssh-agent, and ssh-add (#154)

v0.7.0 [2022-10-19]

Added

  • Add the log-public-key input that can be used to turn off logging key identities (#122)

Fixed

  • Fix path to git binary on Windows, assuming GitHub-hosted runners (#136, #137)
  • Fix a nonsensical log message (#139)

v0.6.0 [2022-10-19]

Changed

v0.5.4 [2021-11-21]

Fixed

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [webfactory/ssh-agent](https://github.com/webfactory/ssh-agent) from 0.9.0 to 0.9.1.
- [Release notes](https://github.com/webfactory/ssh-agent/releases)
- [Changelog](https://github.com/webfactory/ssh-agent/blob/master/CHANGELOG.md)
- [Commits](webfactory/ssh-agent@dc588b6...a6f90b1)

---
updated-dependencies:
- dependency-name: webfactory/ssh-agent
  dependency-version: 0.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Dec 29, 2025
@hyperpolymath
hyperpolymath merged commit 7fa3522 into main Dec 29, 2025
2 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/webfactory/ssh-agent-0.9.1 branch December 29, 2025 08:52
hyperpolymath added a commit that referenced this pull request Jun 16, 2026
#505)

## What
Adds a `rustls-webpki` version detector to the existing Cargo.lock rule
block in `lib/rules/rules.ex` (same pattern as `ring`, `yamux`, `atty`),
plus a fix suggestion in `security_errors.ex`.

- Matches `rustls-webpki` `0.101.*`, `0.102.*`, `0.103.0–0.103.12`;
severity **HIGH**.
- **GHSA-82j2-j2ch-gfr8** == **RUSTSEC-2026-0104** (CVSS 7.5, CWE-125,
DoS via panic on malformed CRL BIT STRING). Fixed `0.103.13`.
- **Non-auto-fixable** (not added to `@auto_fixable`) → security
findings go to manual review.
- Auto-wired: `scan_file` already runs the Cargo.lock branch, so no
orchestration change is needed for this detector.

## Why
Closes the **detection gap** for the transitive/lockfile-only class of
advisories that Dependabot frequently will **not** auto-PR — the exact
class that left `hyperpolymath/007` Dependabot alert #4 (issue #16)
open. Part of the **P0 estate dependency-security control-plane**
completion (baseline:
`dev-notes/2026-06-16-estate-dependency-security-control-plane.md`).

## Validation
- Elixir parse-check passes on both files. Full `mix compile`/CI will
confirm.
- Commit ssh-signed; branch cut from fresh `origin/main`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Sep 27, 2026
… toolchain policy (21 issues fixed, 3 filed) (#867)

Addresses the open issue set of `hyperpolymath/hypatia` in line with
`rsr-template-repo` and `standards`, plus items needing immediate
attention. One commit (`30e6d14`, five logical waves), 21 issues
fixed/resolved, 3 new issues filed from findings, everything else
triaged below.

> **Note on issue comments:** the GitHub integration used here can
create issues but is refused `issue comment` / `issue close` (HTTP 403
"Resource not accessible by integration"). Per-issue dispositions live
in this body instead; `Closes #…` keywords below will close the resolved
set on merge.

## Wave 1 — CI truth

- **#841** — `--locked` now passed on every test/check job (`cargo`
invocations across tests.yml, ci.yml, verify-proofs.yml,
abi-codegen-drift.yml, batch-security-scan).
- **#814** — real cause of red `cargo test --workspace` is the
unsatisfiable `testcontainers ^0.28` vs `testcontainers-modules ^0.15`
pair (not "network egress"); versions made satisfiable and DEBT-REGISTER
CI-1's cause attribution corrected.
- **#847–#851** — `security-policy.yml` consolidated to one scan tier
with a `security-status` aggregator gating `Fail on critical security
findings`; TruffleHog Gates A/B (verified-only off + historical scan);
audit jobs keep and report their findings; container-scan joins the
aggregator; scanner image pinned by explicit tag (`latest` removed).
Decision record + per-step manifest at the top of the workflow.

## Wave 2 — runtime safety

- **#857** — `RateLimiterTest` "tracks active bots" flake: tests now own
named instances via `start_supervised!` (no sleeps); the drain crasher
(`finding.type` KeyError on string-keyed maps) cannot take the limiter
down (try/rescue/catch on dispatch; `check_internal/2` mirrors the full
check incl. burst); crash-isolation regression test proves owned stats
survive `GenServer.whereis(RateLimiter)` being killed.
- **#853** — CI-dead `integration/` compose tier deleted.

## Wave 3 — proofs

- **#820** — `verify-proofs.yml` + `abi-codegen-drift.yml`:
single-prefix Idris2 bootstrap (`make install PREFIX="$HOME/.idris2"`,
no sudo), cache key `-3`, PATH export, measurement step printing `idris2
--prefix/--libdir` + support-lib layout. The abi repair step is retained
with a sequencing comment: delete it only after a green `-3` run prints
"support installation already complete".
- **#816** — `scripts/check-proof-status.sh` (new): PROOF-STATUS rows
named in docs must exist; Property identifiers must match. Green on tree
("files named 27, identifiers checked 7, mismatches 0"); mutants killed
both directions (renamed identifier → red; doc pointing at nonexistent
file → red); `proof-status` job in verify-proofs.yml.
- **#831** — `scripts/check-trusted-base.sh` (new): zero escape hatches
outside `test/soundness/fixtures/`. Tree measured 2026-09-26 (marker
files = `RuleEngine.idr` comments + 6 fixtures; 0
assert_total/postulate/%hint/native_decide/admit in code). Run:
"fixture=19 allowed=1 comment=1 debt=0"; mutant killed (`believe_me`
planted in `verify/src/PipelineState.idr` → DEBT red).
`docs/proof-debt.adoc` counts re-derived (6, obj_magic was missing);
`AFFIRMATION.adoc` claim scoped "outside test/soundness/fixtures/".
`check-trusted-base` job in verify-proofs.yml (5 jobs now: type-check,
lake-build, tlc, proof-status, check-trusted-base).

## Wave 4 — toolchain & policy

- **#832** — `mise.toml` no longer provisions python/denojs or the
Python-only toolchain (pip/black/isort/ruff/pytest, `PYTHON*` env);
`language-blockers.yml` now enforces LANGUAGE-POLICY (Deno manifests
banned; TS/ReScript sources banned — whole-tree, measured 0; banned
runtimes cannot silently return to `mise.toml`) instead of its inverse
("Use Deno instead"). The old TS gate was structurally broken (depth-1
checkout vs `git diff HEAD~1`) and inverted (it blocked `bun.lockb`
telling you to use Deno). Checks green; mutant (planted `python =
"latest"`) caught.
- **#825** — pinning decision recorded in
`docs/governance/ACTIONS-PINNING.adoc` (linked from README):
`actions.lock` is the pinning mechanism for symbolic refs (option (b)) —
no partial SHA sweep. Evidence the lock catches a moved ref is in
DEBT-REGISTER CI-1's own runner log ("Lockfile pin … does not match
ref"). Residual: one deliberate retag-mutant drill.
- **#845** — `mirror.yml` pins standards' `mirror-reusable.yml` at
`2479cf76`, past the Gitea empty-host fault (host/fingerprint vars now
asserted non-empty and named, SSH host keys fingerprint-verified,
per-forge skip notices). New `Mirror coverage` job reports the
denominator (N of 7 configured). Disroot/Bitbucket deploy-key
registration remains owner action (legible via skip notices). Residual:
verify-a-mirror-landed-by-remote-SHA (AC5) needs per-forge remote read.
- Also: two broken README links fixed (`DEBT-REGISTER.md` → `.adoc`;
`PALIMPSEST.adoc` now points at `hyperpolymath/standards` where the file
lives).

## Wave 5 — scanner precision & docs

- **#834** — the comment-matching and line-1 defects, mechanism-level:
Zig comment stripping (`//` incl `///`/`//!`); `scan_content` reports
real line numbers (sarif `region.startLine` no longer defaults to 1);
inline `hypatia:ignore <rule>` / `hypatia: allow code_safety/<rule>`
directives honoured per line; `ffi/zig/src/main.zig`'s opaque-handle
casts carry reviewed pragmas (cast code unchanged); RE005 strips YAML
comments before matching and honours `hypatia:ignore RE005 -- <reason>`.
Both directions fixtured everywhere.
- **#676** — deterministic language resolution: one shared
`CrossRepoLearning.primary_language_from_scan_data/1` (declared field →
count desc → fixed priority → lexical; total order), used by all three
readers. Discriminating test fails on the old `Enum.max_by` tie-break,
passes now. Producer-side array ordering is outside this repo →
**#866**.
- **#746/#748** — secret findings dispositioned: placeholder-shaped
values (`xxx`-runs, ellipses, `your-*`, `changeme`, `<…>`) and
whole-line comments demote to `medium`/`report` with an explicit reason;
an uncommented real-looking value stays
`critical`/`revoke_rotate_and_purge`. The 45 measured blocking false
positives all fall in the demoted class; nothing is silenced.
Harvested-corpus carve-out → **#865**.
- **#636** — category-A purge only: Logtalk-as-current claims
removed/annotated from ci.yml header, ROADMAP (3), poc-scanner.sh (2),
developer-guide (install + toolchain + diagram + data-flow), admin-guide
(6), cicd-guidebook (2), NEURAL-ARCHITECTURE present tense; PROOF-STATUS
Logtalk claims annotated with reason (status unchanged). B/C/D
untouched: `hooks/lib/common.sh`, `lib/rules` migration comments, 6a2
purge records, `MUST.contractile` (owner-gated → **#864**),
`.audittraining`, arcvix paper, system-integration's own residual note.
- **#695** — PMPL drift fixed in governance/hypatia-scan/scorecard
headers (dogfooding `fix-pmpl-drift.sh`'s own fix); SPDX added to
`test_helper.exs`, `test_integration.exs`, both `check-*.sh`,
`docs/proof-debt.adoc`; `integration/fixtures/test-repo/src/main.rs`
stays deliberately headerless (recorded in new `.reuse/dep5`, which also
covers the docs/training corpus); unused
`LICENSES/AGPL-3.0-or-later.txt` removed; `CITATION.cff` added;
`.github/TEST_CI_CODEQL_HYPATIA.md` deleted per its own "DELETE AFTER
VERIFICATION" instruction; `mix hypatia.rsr_score` resolves its SSOT
from real source-tree candidates — the bare command works without
`--ssot` (the old `:code.priv_dir/..` path landed inside `_build`).
Stale sub-items confirmed done elsewhere: mise.toml (#832),
descriptiles/ migration (6a2/ gone), guix.scm (deleted), #417 (already
closed).

## New issues filed (found during this work, not merge blockers)

- **#864** — owner-gated: `MUST.contractile:79` "Logtalk rule engine …
must be preserved" contradicts the retired engine (#636 category C,
doctrine #4: supervised decision).
- **#865** — `harvested-registry/` reference material trips
`secret_detected`; path-based carve-out proposal (#746 tail note).
- **#866** — the verisimdb `scans/` writer lives outside hypatia;
edges/rows/attacks must be sorted at *its* emit boundary (the #676
producer-side half).

## Triage of the remaining open set

| # | disposition |
|---|---|
| 358, 359 | panic-attack fact-source / higher-order rules — design
work, unchanged; no blocker found this pass |
| 361, 363, 366 | #333 cohort detector ideas — additive rules; valid
backlog |
| 367 | M20 SNIF parser port — blocked on its upstream unlock
(hypatia#294), untouched |
| 369 | code-scanning→dispatch loop RFC — the `security-status`
aggregator pattern from #847 is a building block |
| 421 | `reusable_workflow_sha_bump_needs_propagation` wiring — real;
registry+dispatch wiring still missing |
| 447–449 | taxonomy/self-model/planner RFCs — out of scope for this
pass |
| 463–466 | estate ops queues (billing wall, red CI, licence PRs, PR
stewardship) — owner-facing, unchanged |
| 470, 471, 473 | ruleset audits — `ABI-Codegen-Drift` is the only
active hypatia ruleset (verified); estate-wide Base ruleset audit still
open |
| 483 | doc + contractile currency — #636/#695/#864 are slices of it |
| 485 | rsr-template↔standards divergence audit — needs
owner/consistency-plugin access |
| 486 | neural-convergence proofs — needs network+Mathlib; out of pass |
| 519 | `Hypatia` check must report on every PR — related to the #847
aggregator design; still open |
| 520 | stale `standards` reusable pins estate-wide — hypatia's own
`mirror.yml` pin bumped to `2479cf76` in this PR; the estate sweep
remains (and `check-lockfile-drift.sh` mode 4 is the detector) |
| 523, 554, 556 | scanner deployment/verification ops — unchanged |
| 567 | cicd-squabbler feedback channel — design, unchanged |
| 582 | ScorecardReconciler scheduling — unchanged |
| 585 | ruleset gate-deadlock (structurally-unsatisfiable required
checks) — owner/ruleset-admin action; the accept-or-delete ruling
applies |
| 605 | B-SHAPIN + `actions_policy.ex` — valid detection backlog |
| 638 | allowlist heal-then-wipe oscillation — ops, unchanged |
| 683 | CI-health estate failure-class report — ops cadence, unchanged |
| 676 | **kept open** — hypatia side fixed (see above); the
producer-side half is #866 |
| 845 | **kept open** — Gitea empty-host fault fixed via pin bump;
Disroot/Bitbucket key registration (owner) + remote-SHA verification
(AC5) remain |

## Evidence & limits

- All new scripts were run green on the tree and mutant-proven both
directions (detailed in each commit message). Scanner rule changes ship
with both-directions fixtures.
- No Elixir/Rust toolchain exists in the fix sandbox: `mix test` /
`cargo test` assertions are written to run in CI on this branch and
constitute the test-level acceptance evidence.
- `actions.lock` kept set-equal to workflow refs (both third-party
action tags are `v7.0.1`/`v4.32.0`, matching the lock's recorded
resolutions).

Closes #814, closes #816, closes #820, closes #825, closes #831, closes
#832, closes #834, closes #841, closes #847, closes #848, closes #849,
closes #850, closes #851, closes #853, closes #857, closes #636, closes
#695, closes #746, closes #748

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant