From 826ef62d5ca3fee1f7836b76b9054245f7852b72 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:07:37 +0100 Subject: [PATCH 1/2] fix(ci): regenerate actions.lock for codeql-action v4.38.1 and wiki-sync Main b7c780f carries three reds from one stale lockfile: CodeQL startup_failure (run 36270651549), Governance "Actions lockfile verify" (36270650148) and Scorecard reconcile exit 2 (36378742440). `gh actions-lock --verify-local` on b7c780f reported three errors: codeql.yml moved to github/codeql-action@v4.38.1 while the lock still pinned v4.38.0 (ref-changed x2), and wiki-sync.yml uses actions/checkout@v7.0.1 with no lock entry (not-pinned). Regenerated with standards scripts/update-actions-lock.sh at standards main 5f82b63. The updater also dropped ten SHA-keyed dependency entries that no file in the repository references (for example the retired denoland/setup-deno). Verifier after the change: valid, advisory findings only. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57 --- .github/workflows/actions.lock | 60 ++++----------------------------- .github/workflows/wiki-sync.yml | 1 + 2 files changed, 7 insertions(+), 54 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index ccd82a9..7ecea41 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -10,7 +10,7 @@ workflows: - 'google/clusterfuzzlite@v1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' + - 'github/codeql-action@v4.38.1' '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': [] '.github/workflows/label-triage.yml': [] @@ -35,6 +35,8 @@ workflows: '.github/workflows/rust-ci.yml': [] '.github/workflows/scorecard.yml': [] '.github/workflows/secret-scanner.yml': [] + '.github/workflows/wiki-sync.yml': + - 'actions/checkout@v7.0.1' dependencies: 'actions/attest-build-provenance@v4.2.2': ref: 'v4.2.2' @@ -85,9 +87,9 @@ dependencies: commit: 'sha1-dc802804100637a589fabce1cb79ff13a1411302' owner_id: 5429470 repo_id: 306769011 - 'github/codeql-action@v4.38.0': - ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + 'github/codeql-action@v4.38.1': + ref: 'v4.38.1' + commit: 'sha1-1c5b675653bb5c22dbe9b12b556ec555138e09fd' owner_id: 9919 repo_id: 259445878 'google/clusterfuzzlite@v1': @@ -100,53 +102,3 @@ dependencies: commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be' owner_id: 6759885 repo_id: 1352485172 - 'Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4': - ref: 'v2' - commit: 'sha1-c19371144df3bb44fab255c43d04cbc2ab54d1c4' - owner_id: 580492 - repo_id: 298565987 - 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9': - ref: 'v6.1.0' - commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' - owner_id: 44036562 - repo_id: 215566462 - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1': - ref: 'v7.0.1' - commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' - owner_id: 44036562 - repo_id: 197814629 - 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a': - ref: 'v7.0.1' - commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' - owner_id: 44036562 - repo_id: 192625955 - 'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed': - ref: 'v2.0.5' - commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed' - owner_id: 42048915 - repo_id: 356423100 - 'dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c': - ref: 'stable' - commit: 'sha1-2c7215f132e9ebf062739d9130488b56d53c060c' - owner_id: 1940490 - repo_id: 260749683 - 'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c': - ref: 'v2.2.0' - commit: 'sha1-840e866d93b8e032123c23bac69dece044d4d84c' - owner_id: 26415196 - repo_id: 297874902 - 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124': - ref: 'v1.24.1' - commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' - owner_id: 47606891 - repo_id: 331103973 - 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc': - ref: 'v2.4.4' - commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc' - owner_id: 67707773 - repo_id: 421101922 - 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555': - ref: 'v0.10.0' - commit: 'sha1-e83874834305fe9a4a2997156cb26c5de65a8555' - owner_id: 135788 - repo_id: 208510314 diff --git a/.github/workflows/wiki-sync.yml b/.github/workflows/wiki-sync.yml index 28ca02f..cbd10c7 100644 --- a/.github/workflows/wiki-sync.yml +++ b/.github/workflows/wiki-sync.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Wiki Sync From 47ac00dc18dad3aebd4f2e4d4264ffc334829177 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:20:31 +0100 Subject: [PATCH 2/2] fix(ci): scope wiki-sync's contents: write to the job that pushes Hypatia WH002 flagged the top-level `permissions: contents: write` on wiki-sync.yml. The top level is now `contents: read`, and the single `sync` job carries `contents: write`, because scripts/wiki-sync.sh does push to the wiki with GITHUB_TOKEN. Behaviour is unchanged; the grant is no longer inherited by any job added later. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57 --- .github/workflows/wiki-sync.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/wiki-sync.yml b/.github/workflows/wiki-sync.yml index cbd10c7..ba16ac7 100644 --- a/.github/workflows/wiki-sync.yml +++ b/.github/workflows/wiki-sync.yml @@ -12,7 +12,7 @@ on: workflow_dispatch: permissions: - contents: write + contents: read concurrency: group: wiki-sync @@ -21,6 +21,9 @@ concurrency: jobs: sync: runs-on: ubuntu-latest + # Write is scoped to this job only: scripts/wiki-sync.sh pushes to the wiki. + permissions: + contents: write timeout-minutes: 10 steps: - uses: actions/checkout@v7.0.1