From e25842b43d30e91a8f06397fd5f31be3eebbf7ac Mon Sep 17 00:00:00 2001 From: samuelburnham <45365069+samuelburnham@users.noreply.github.com> Date: Thu, 1 Oct 2026 12:49:39 -0400 Subject: [PATCH] ci: pin actions to commit SHAs and lint workflows Every third-party `uses:` now carries a full commit SHA with a version comment, the form Dependabot reads to keep the pins fresh. lean-update's `dev` and the shared ci-workflows actions on `main` are branch refs with no tag to pin to; `.github/pinact.yaml` exempts them and `.github/zizmor.yml` gives them a ref-pin policy. A `lints` job calls ci-workflows' lint-workflows action (actionlint, shellcheck over composite action scripts, pinact check and verify, zizmor). Getting zizmor clean: the CI workflow declares `contents: read` instead of inheriting the repository default, every checkout sets `persist-credentials: false` (lean-update pushes through its own token input, not the checkout's git credentials), the Nix installer reads `github.token`, and Dependabot gets the 7-day cooldown zizmor requires. Dependabot now also covers the Rust crate under `rust/`, which had no cargo ecosystem entry. The valgrind job restored a cache from `test/.lake` keyed on a `test/lake-manifest.json` that does not exist, so it always rebuilt from scratch; it now restores the root `.lake` under the key lean-action saves in the lean-test job. --- .github/dependabot.yml | 15 ++++++++++ .github/pinact.yaml | 9 ++++++ .github/workflows/ci.yml | 53 ++++++++++++++++++++++++++---------- .github/workflows/update.yml | 8 ++++-- .github/zizmor.yml | 8 ++++++ 5 files changed, 75 insertions(+), 18 deletions(-) create mode 100644 .github/pinact.yaml create mode 100644 .github/zizmor.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml index dbd4f71..d2746ef 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,9 +1,24 @@ version: 2 updates: + - package-ecosystem: "cargo" + directory: "/rust" + pull-request-branch-name: + separator: "-" + schedule: + interval: "weekly" + cooldown: + default-days: 7 + groups: + rust-dependencies: + patterns: + - "*" + - package-ecosystem: "github-actions" directory: "/" schedule: interval: "weekly" + cooldown: + default-days: 7 groups: actions-dependencies: patterns: diff --git a/.github/pinact.yaml b/.github/pinact.yaml new file mode 100644 index 0000000..75ff053 --- /dev/null +++ b/.github/pinact.yaml @@ -0,0 +1,9 @@ +version: 3 +rules: + # Branch refs that must keep tracking their branch: there is no stable tag + # to pin to. lean-update's `dev` carries the fork's features, and the shared + # ci-workflows actions are consumed from `main`. + - ignore: true + conditions: + - expr: ActionName == "argumentcomputer/lean-update" + - expr: ActionName matches "^argumentcomputer/ci-workflows/" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0b33c99..60d08dd 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,6 +7,9 @@ on: - main workflow_dispatch: +permissions: + contents: read + concurrency: group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} cancel-in-progress: true @@ -16,9 +19,11 @@ jobs: name: Lean Tests runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: actions-rust-lang/setup-rust-toolchain@v2 - - uses: leanprover/lean-action@v1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: actions-rust-lang/setup-rust-toolchain@ecabd13d1c56bd1345c230e542e9144811ad706f # v2.0.0 + - uses: leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596 # v1.6.0 with: build-args: "--wfail" test: true @@ -27,15 +32,20 @@ jobs: needs: lean-test runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: actions-rust-lang/setup-rust-toolchain@v2 - # Only restore the cache, since the `test` job will save the test binary to the cache first - - uses: actions/cache/restore@v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - path: ./test/.lake - key: lake-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('lean-toolchain') }}-${{ hashFiles('test/lake-manifest.json') }}-${{ github.sha }} - restore-keys: lake-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('lean-toolchain') }}-${{ hashFiles('test/lake-manifest.json') }} - - uses: leanprover/lean-action@v1 + persist-credentials: false + - uses: actions-rust-lang/setup-rust-toolchain@ecabd13d1c56bd1345c230e542e9144811ad706f # v2.0.0 + # Restore the `.lake` that lean-action saved in the lean-test job for + # this commit, so the test binary is not rebuilt from scratch. Restore + # only: lean-action below runs with its cache off to avoid a second save + # under the same key. + - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: ./.lake + key: lake-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('lean-toolchain') }}-${{ hashFiles('lake-manifest.json') }}-${{ github.sha }} + restore-keys: lake-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('lean-toolchain') }}-${{ hashFiles('lake-manifest.json') }} + - uses: leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596 # v1.6.0 with: auto-config: false build: true @@ -57,12 +67,14 @@ jobs: name: Nix Tests runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 - - uses: cachix/install-nix-action@v31 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: nix_path: nixpkgs=channel:nixos-unstable - github_access_token: ${{ secrets.GITHUB_TOKEN }} - - uses: cachix/cachix-action@v17 + github_access_token: ${{ github.token }} + - uses: cachix/cachix-action@38b082610b782e7e93e209c35fd730d399dee866 # v17 with: name: argumentcomputer authToken: ${{ secrets.CACHIX_AUTH_TOKEN }} @@ -74,3 +86,14 @@ jobs: # Catch-all: near-free after the steps above; fails if a check is added # to the flake without a step here. - run: nix flake check --accept-flake-config + + lints: + name: Lint workflows + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + # actionlint, shellcheck over composite action scripts, pinact (actions + # must be SHA-pinned with a matching version comment) and zizmor + - uses: argumentcomputer/ci-workflows/.github/actions/lint-workflows@main diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index b84c49f..94a8b9d 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -14,11 +14,13 @@ jobs: update: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - - uses: cachix/install-nix-action@v31 + - uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1 with: - github_access_token: ${{ secrets.GITHUB_TOKEN }} + github_access_token: ${{ github.token }} # `dev` carries pinned-tag updates and lean4-nix gating; `main` only # mirrors upstream and ignores these inputs. diff --git a/.github/zizmor.yml b/.github/zizmor.yml new file mode 100644 index 0000000..576392f --- /dev/null +++ b/.github/zizmor.yml @@ -0,0 +1,8 @@ +rules: + unpinned-uses: + config: + policies: + # Branch-tracking refs allowed by .github/pinact.yaml + "argumentcomputer/lean-update": ref-pin + "argumentcomputer/ci-workflows/*": ref-pin + "*": hash-pin