diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index c008c8f..c1dac4d 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -49,67 +49,51 @@ dependencies: repo_id: 760702757 uses: - 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d' - 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d': ref: 'v4.2.1' commit: 'sha1-508db95dd578ae2727ebd6217d5ba78e4fbda05d' owner_id: 44036562 repo_id: 760701061 - 'actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae': ref: 'v5.0.5' commit: 'sha1-27d5ce7f107fe9357f9df03efb73ab90386fccae' owner_id: 44036562 repo_id: 215566462 - 'actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb': ref: 'v5.0.1' commit: 'sha1-9255dc7a253b0ccc959486e2bca901246202afeb' owner_id: 44036562 repo_id: 215566462 - 'actions/cache@v6.1.0': ref: 'v6.1.0' commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' owner_id: 44036562 repo_id: 215566462 - - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1': - ref: 'v7.0.1' - commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' - owner_id: 44036562 - repo_id: 197814629 - 'actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8': ref: 'v6.0.1' commit: 'sha1-8e8c483db84b4bee98b60c0593521ed34d9990e8' owner_id: 44036562 repo_id: 197814629 - 'actions/checkout@v7.0.1': ref: 'v7.0.1' commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' owner_id: 44036562 repo_id: 197814629 - 'actions/configure-pages@v6.0.0': ref: 'v6.0.0' commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' owner_id: 44036562 repo_id: 513659658 - 'actions/deploy-pages@v5.0.1': ref: 'v5.0.1' commit: 'sha1-368f82528645a54fb793d4d04e342629a3f51346' owner_id: 44036562 repo_id: 438112499 - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f': ref: 'v7.0.0' commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' owner_id: 44036562 repo_id: 192625955 - 'actions/upload-pages-artifact@v5.0.0': ref: 'v5.0.0' commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9' @@ -117,7 +101,6 @@ dependencies: repo_id: 496012378 uses: - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' - 'aquasecurity/setup-trivy@3fb12ec12f41e471780db15c232d5dd185dcb514': ref: 'v0.2.6' commit: 'sha1-3fb12ec12f41e471780db15c232d5dd185dcb514' @@ -126,7 +109,6 @@ dependencies: uses: - 'actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb' - 'actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8' - 'aquasecurity/trivy-action@v0.36.0': ref: 'v0.36.0' commit: 'sha1-ed142fd0673e97e23eac54620cfb913e5ce36c25' @@ -135,55 +117,46 @@ dependencies: uses: - 'actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae' - 'aquasecurity/setup-trivy@3fb12ec12f41e471780db15c232d5dd185dcb514' - 'dependabot/fetch-metadata@v3.1.0': ref: 'v3.1.0' commit: 'sha1-25dd0e34f4fe68f24cc83900b1fe3fe149efef98' owner_id: 27347476 repo_id: 371068214 - 'docker/build-push-action@v7.3.0': ref: 'v7.3.0' commit: 'sha1-53b7df96c91f9c12dcc8a07bcb9ccacbed38856a' owner_id: 5429470 repo_id: 241092383 - 'docker/login-action@v4.6.0': ref: 'v4.6.0' commit: 'sha1-dbcb813823bdd20940b903addbd779551569679f' owner_id: 5429470 repo_id: 287743349 - 'docker/metadata-action@v6.2.0': ref: 'v6.2.0' commit: 'sha1-dc802804100637a589fabce1cb79ff13a1411302' owner_id: 5429470 repo_id: 306769011 - 'docker/setup-buildx-action@v4.3.0': ref: 'v4.3.0' commit: 'sha1-37fe631027851001ddb9b187196cc803df7f5f0e' owner_id: 5429470 repo_id: 288485773 - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63': ref: 'v4.38.0' commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' owner_id: 9919 repo_id: 259445878 - 'github/codeql-action@v4.38.0': ref: 'v4.38.0' commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' owner_id: 9919 repo_id: 259445878 - 'haskell-actions/setup@v2.12.0': ref: 'v2.12.0' commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d' owner_id: 75048950 repo_id: 623796603 - 'peter-evans/repository-dispatch@v4.0.1': ref: 'v4.0.1' commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 9077005..855c2e6 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: GitHub Pages @@ -22,19 +23,19 @@ jobs: timeout-minutes: 60 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -75,9 +76,9 @@ jobs: fi cd .casket-ssg && cabal run casket-ssg -- build ../site ../_site - name: Setup Pages - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 + uses: actions/configure-pages@v6.0.0 - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -90,4 +91,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5e0e85e..1c90fd4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell @@ -20,14 +21,14 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Setup Haskell - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: "9.4" cabal-version: "3.10" - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -50,9 +51,9 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Cache cargo - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cargo/registry @@ -81,7 +82,7 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check shell wrapper syntax run: bash -n bot-integration-affine/check.sh security: @@ -93,9 +94,9 @@ jobs: security-events: write steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 + uses: aquasecurity/trivy-action@v0.36.0 with: scan-type: "fs" scan-ref: "." @@ -104,7 +105,7 @@ jobs: output: "trivy-results.sarif" continue-on-error: true - name: Upload Trivy scan results - uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/upload-sarif@v4.38.0 with: sarif_file: "trivy-results.sarif" continue-on-error: true diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 825ec52..3c204e1 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: CodeQL Security Analysis @@ -31,7 +32,7 @@ jobs: build-mode: none steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Initialize CodeQL diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 3c746fc..9456369 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # @@ -55,7 +56,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + uses: dependabot/fetch-metadata@v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} # --- Policy gate ------------------------------------------------------- diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 4a1afdb..141e451 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Governance diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 64d6033..763f8a6 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Hypatia Security Scan diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index c028b4e..a20dd8e 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release @@ -27,7 +28,7 @@ jobs: fi - name: Trigger Propagation if: steps.credential.outputs.available == 'true' - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1 + uses: peter-evans/repository-dispatch@v4.0.1 with: token: ${{ secrets.FARM_DISPATCH_TOKEN }} repository: hyperpolymath/.git-private-farm diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 7c9cf0c..887ce6d 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index 31679d8..909584a 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Labels diff --git a/.github/workflows/language-policy.yml b/.github/workflows/language-policy.yml index 416c0da..a569b27 100644 --- a/.github/workflows/language-policy.yml +++ b/.github/workflows/language-policy.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Language Policy Enforcement @@ -20,7 +21,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Enforce language policies run: | # Block new Python files (except SaltStack) diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index bd1d7e1..3a0f0c7 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Mirror to Git Forges diff --git a/.github/workflows/publish-image.yml b/.github/workflows/publish-image.yml index 7ddec64..21d1fd0 100644 --- a/.github/workflows/publish-image.yml +++ b/.github/workflows/publish-image.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell @@ -36,18 +37,18 @@ jobs: attestations: write steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + uses: docker/setup-buildx-action@v4.3.0 - name: Log in to GHCR - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + uses: docker/login-action@v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta - uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 + uses: docker/metadata-action@v6.2.0 with: images: ghcr.io/hyperpolymath/oikos flavor: | @@ -58,7 +59,7 @@ jobs: type=sha - name: Build and push id: push - uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 + uses: docker/build-push-action@v7.3.0 with: context: . file: ./Containerfile @@ -68,7 +69,7 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max - name: Attest container provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-name: ghcr.io/hyperpolymath/oikos subject-digest: ${{ steps.push.outputs.digest }} diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index a47623e..cb32e42 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: OSSF Scorecard diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 470bf74..637da5e 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Secret Scanner diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 7b635d3..b35eff2 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config @@ -15,7 +16,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Check SPDX headers run: | errors=0