Skip to content

fix(ci): regenerate actions.lock for codeql-action v4.38.1 and wiki-sync - #178

Merged
hyperpolymath merged 2 commits into
mainfrom
chore/refresh-actions-lock
Sep 30, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
chore/refresh-actions-lock

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Main b7c780f carries three reds from one stale lockfile: CodeQL
startup_failure (run 36270651549), Governance "Actions lockfile verify"
(36270650148) and Scorecard reconcile exit 2 (36378742440).

gh actions-lock --verify-local on b7c780f reported three errors:
codeql.yml moved to github/codeql-action@v4.38.1 while the lock still
pinned v4.38.0 (ref-changed x2), and wiki-sync.yml uses
actions/checkout@v7.0.1 with no lock entry (not-pinned).

Regenerated with standards scripts/update-actions-lock.sh at standards
main 5f82b63. The updater also dropped ten SHA-keyed dependency entries
that no file in the repository references (for example the retired
denoland/setup-deno). Verifier after the change: valid, advisory
findings only.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

Acceptance criteria

  1. CodeQL on this PR runs with jobs > 0 (no startup_failure).
  2. Governance "Actions lockfile verify" is green.
  3. Scorecard reconcile exits 0.
  4. No other workflow regresses to startup_failure, which would show that one of the dropped entries was a live transitive edge.

After this lands, #177 is updated onto it and landed only fully green, and #176 is closed (owner ruling D220 on hyperpolymath/standards#787).

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

Main b7c780f carries three reds from one stale lockfile: CodeQL
startup_failure (run 36270651549), Governance "Actions lockfile verify"
(36270650148) and Scorecard reconcile exit 2 (36378742440).

`gh actions-lock --verify-local` on b7c780f reported three errors:
codeql.yml moved to github/codeql-action@v4.38.1 while the lock still
pinned v4.38.0 (ref-changed x2), and wiki-sync.yml uses
actions/checkout@v7.0.1 with no lock entry (not-pinned).

Regenerated with standards scripts/update-actions-lock.sh at standards
main 5f82b63. The updater also dropped ten SHA-keyed dependency entries
that no file in the repository references (for example the retired
denoland/setup-deno). Verifier after the change: valid, advisory
findings only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 47 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c4281329-b2c0-49ea-a9c5-488a51446127

📥 Commits

Reviewing files that changed from the base of the PR and between 826ef62 and 47ac00d.

📒 Files selected for processing (1)
  • .github/workflows/wiki-sync.yml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: af5d4f18-aac5-4337-a15a-da0442fc2e46

📥 Commits

Reviewing files that changed from the base of the PR and between b7c780f and 826ef62.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • .github/workflows/wiki-sync.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (21)
  • GitHub Check: scan / rust-secrets
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: scan / shell-secrets
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: scan / gitleaks
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Security policy checks
  • GitHub Check: rust-ci / Detect Cargo.toml
  • GitHub Check: scorecard / Run Scorecard PR
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: analyze (rust, none)
  • GitHub Check: analyze (actions, none)
  • GitHub Check: PR (address)
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
.github/workflows/wiki-sync.yml (1)

1-1: LGTM!


📝 Summary

Summary by CodeRabbit

  • Documentation
    • Added a note clarifying that the workflow is managed by an automated tool.

Walkthrough

The wiki sync workflow gains a comment stating that gh actions-lock manages the workflow. No workflow behaviour changes.

Changes

Workflow ownership

Layer / File(s) Summary
Workflow management comment
.github/workflows/wiki-sync.yml
Adds a comment identifying the workflow as managed by gh actions-lock. No workflow behaviour changes.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 826ef

This change updates the CodeQL pin and adds the wiki-sync lock entry without changing workflow behavior. No introduced merge-blocking risk was identified; normal checks should still pass.

Architecture Summary

Architecture risk: 🔵 Low · up to 826ef

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/wiki-sync.yml: Added a comment identifying the workflow as managed by gh actions-lock.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the lockfile regeneration and names the affected CodeQL action version and wiki-sync workflow.
Description check ✅ Passed The description directly explains the stale lockfile errors, the regeneration process, and the acceptance criteria for the workflow fixes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit notes the workflow’s keeper.
One comment marks the tool in place.
No steps change their course or pace.
The wiki sync stays as before.
The rabbit hops away once more.

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/wiki-sync.yml Fixed
coderabbitai[bot]
coderabbitai Bot previously approved these changes Sep 30, 2026
Hypatia WH002 flagged the top-level `permissions: contents: write` on
wiki-sync.yml. The top level is now `contents: read`, and the single
`sync` job carries `contents: write`, because scripts/wiki-sync.sh does
push to the wiki with GITHUB_TOKEN. Behaviour is unchanged; the grant is
no longer inherited by any job added later.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@hyperpolymath
hyperpolymath merged commit 5613b0e into main Sep 30, 2026
37 checks passed
@hyperpolymath
hyperpolymath deleted the chore/refresh-actions-lock branch September 30, 2026 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants