Finding
governance / Actions lockfile verify is red on main at 300fd45 (run 36729214094). Dependabot bumped uses: refs without refreshing .github/actions.lock:
| action |
lockfile pins |
workflows use |
where |
| taiki-e/install-action |
v2.87.18 |
v2.87.21 |
build-gossamer-gui, ci, security-policy, tests |
| haskell-actions/setup |
v2.12.0 |
v2.12.1 |
ci |
| ruby/setup-ruby |
v1.324.0 |
v1.327.0 |
quality |
| trufflesecurity/trufflehog |
v3.97.6 |
v3.97.9 |
security-policy |
| github/codeql-action |
bare SHA b96794f… (sha-as-ref, stale) |
— |
codeql, security-policy |
The check is not required on main, so it does not block merges. It is inherited by every open PR, e.g. #884, which touches no workflow file.
Acceptance criteria
🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
Finding
governance / Actions lockfile verifyis red onmainat 300fd45 (run 36729214094). Dependabot bumpeduses:refs without refreshing.github/actions.lock:b96794f…(sha-as-ref, stale)The check is not required on
main, so it does not block merges. It is inherited by every open PR, e.g. #884, which touches no workflow file.Acceptance criteria
.github/actions.lockpins exactly the refs the workflows use (the 4ref-changedrows above), each with its resolved commit SHA (not a tag-object SHA).sha-as-reffindings remain.governance / Actions lockfile verifyis green on a PR againstmain, and after merge onmainitself.gh actions-lockrewrite mode is known to de-pin SHAs to tags and corrupt local action refs.🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK