diff --git a/.github/workflows/abi-drift.yml b/.github/workflows/abi-drift.yml index f214931a..3ef358d9 100644 --- a/.github/workflows/abi-drift.yml +++ b/.github/workflows/abi-drift.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # ABI Drift Gate (standards#92 Phase 2) @@ -77,7 +78,7 @@ jobs: fetch-depth: 0 - name: Install Rust toolchain (stable) - uses: dtolnay/rust-toolchain@b3b07ba8b418998c39fb20f53e8b695cdcc8de1b # stable + uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master with: toolchain: stable diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 00000000..798074d1 --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,212 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/abi-drift.yml': + - 'actions/cache@v4.2.2' + - 'actions/checkout@v6.0.2' + - 'dtolnay/rust-toolchain@master' + '.github/workflows/backend-assurance.yml': + - 'actions/cache@v4.2.2' + - 'actions/checkout@v6.0.2' + - 'erlef/setup-beam@v1.24.0' + '.github/workflows/build.yml': + - 'actions/checkout@v4.3.1' + - 'sonarsource/sonarqube-scan-action@v8.1.0' + '.github/workflows/codeql.yml': + - 'actions/checkout@v6.0.2' + - 'github/codeql-action@v4.34.0' + '.github/workflows/container-publish.yml': + - 'actions/attest-build-provenance@v2.4.0' + - 'actions/checkout@v6.0.2' + '.github/workflows/dogfood-gate.yml': + - 'actions/checkout@v6.0.2' + '.github/workflows/e2e.yml': + - 'actions/checkout@v6.0.2' + - 'actions/github-script@v8.0.0' + - 'actions/setup-node@v4.4.0' + - 'actions/upload-artifact@v4.6.2' + - 'denoland/setup-deno@v2.0.4' + - 'erlef/setup-beam@v1.24.0' + - 'goto-bus-stop/setup-zig@v2.0.0' + - 'oven-sh/setup-bun@v2.2.0' + '.github/workflows/fuzz.yml': + - 'actions/checkout@v6.0.2' + - 'mlugg/setup-zig@v2.2.1' + '.github/workflows/hcg-surface-drift.yml': + - 'actions/checkout@v6.0.2' + '.github/workflows/hypatia-scan.yml': + - 'actions/checkout@v6.0.2' + - 'actions/github-script@v8.0.0' + - 'actions/upload-artifact@v4.6.2' + - 'erlef/setup-beam@v1.24.0' + - 'github/codeql-action@v4.32.6' + '.github/workflows/instant-sync.yml': + - 'peter-evans/repository-dispatch@v3.0.0' + '.github/workflows/lsp-dap-bsp.yml': + - 'actions/checkout@v6.0.2' + - 'goto-bus-stop/setup-zig@v2.0.0' + '.github/workflows/pages-deploy.yml': + - 'actions/checkout@v4.4.0' + '.github/workflows/pages.yml': + - 'actions/checkout@v4.4.0' + - 'actions/deploy-pages@v4.0.5' + - 'actions/upload-pages-artifact@v3.0.1' + '.github/workflows/proofs.yml': + - 'actions/cache@v4.2.2' + - 'actions/checkout@v6.0.2' + '.github/workflows/publish.yml': + - 'actions/checkout@v6.0.2' + - 'actions/setup-node@v4.4.0' + - 'denoland/setup-deno@v2.0.4' + '.github/workflows/push-email-notify.yml': + - 'dawidd6/action-send-mail@v3.12.0' + '.github/workflows/release.yml': + - 'actions/checkout@v6.0.2' + - 'actions/download-artifact@v4.2.1' + - 'actions/upload-artifact@v4.6.2' + - 'mlugg/setup-zig@v2.2.1' + - 'softprops/action-gh-release@v2.6.2' + '.github/workflows/truthfulness.yml': + - 'actions/checkout@v6.0.2' + - 'goto-bus-stop/setup-zig@v2.0.0' + '.github/workflows/zig-test.yml': + - 'actions/checkout@v6.0.2' + - 'mlugg/setup-zig@v2.2.1' +dependencies: + 'actions/attest-build-provenance@1176ef556905f349f669722abf30bce1a6e16e01': + ref: 'predicate@1.1.5' + commit: 'sha1-1176ef556905f349f669722abf30bce1a6e16e01' + owner_id: 44036562 + repo_id: 760702757 + 'actions/attest-build-provenance@v2.4.0': + ref: 'v2.4.0' + commit: 'sha1-e8998f949152b193b063cb0ec769d69d929409be' + owner_id: 44036562 + repo_id: 760702757 + uses: + - 'actions/attest-build-provenance@1176ef556905f349f669722abf30bce1a6e16e01' + - 'actions/attest@ce27ba3b4a9a139d9a20a4a07d69fabb52f1e5bc' + 'actions/attest@ce27ba3b4a9a139d9a20a4a07d69fabb52f1e5bc': + ref: 'v2.4.0' + commit: 'sha1-ce27ba3b4a9a139d9a20a4a07d69fabb52f1e5bc' + owner_id: 44036562 + repo_id: 760701061 + 'actions/cache@v4.2.2': + ref: 'v4.2.2' + commit: 'sha1-d4323d4df104b026a6aa633fdb11d772146be0bf' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@v4.3.1': + ref: 'v4.3.1' + commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v4.4.0': + ref: 'v4.4.0' + commit: 'sha1-11d5960a326750d5838078e36cf38b85af677262' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v6.0.2': + ref: 'v6.0.2' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'actions/deploy-pages@v4.0.5': + ref: 'v4.0.5' + commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + owner_id: 44036562 + repo_id: 438112499 + 'actions/download-artifact@v4.2.1': + ref: 'v4.2.1' + commit: 'sha1-95815c38cf2ff2164869cbab79da8d1f422bc89e' + owner_id: 44036562 + repo_id: 192626254 + 'actions/github-script@v8.0.0': + ref: 'v8.0.0' + commit: 'sha1-ed597411d8f924073f98dfc5c65a23a2325f34cd' + owner_id: 44036562 + repo_id: 205262760 + 'actions/setup-node@v4.4.0': + ref: 'v4.4.0' + commit: 'sha1-49933ea5288caeca8642d1e84afbd3f7d6820020' + owner_id: 44036562 + repo_id: 189476904 + 'actions/upload-artifact@v4': + ref: 'v4' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-artifact@v4.6.2': + ref: 'v4.6.2' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@v3.0.1': + ref: 'v3.0.1' + commit: 'sha1-56afc609e74202658d3ffba0e8f6dda462b719fa' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@v4' + 'dawidd6/action-send-mail@v3.12.0': + ref: 'v3.12.0' + commit: 'sha1-6e502825a508b867ab2954ad6343b68787624c01' + owner_id: 9713907 + repo_id: 222439721 + 'denoland/setup-deno@v2.0.4': + ref: 'v2.0.4' + commit: 'sha1-667a34cdef165d8d2b2e98dde39547c9daac7282' + owner_id: 42048915 + repo_id: 356423100 + 'dtolnay/rust-toolchain@master': + ref: 'master' + commit: 'sha1-b3b07ba8b418998c39fb20f53e8b695cdcc8de1b' + owner_id: 1940490 + repo_id: 260749683 + 'erlef/setup-beam@v1.24.0': + ref: 'v1.24.0' + commit: 'sha1-fc68ffb90438ef2936bbb3251622353b3dcb2f93' + owner_id: 47606891 + repo_id: 331103973 + 'github/codeql-action@v4.32.6': + ref: 'v4.32.6' + commit: 'sha1-0d579ffd059c29b07949a3cce3983f0780820c98' + owner_id: 9919 + repo_id: 259445878 + 'github/codeql-action@v4.34.0': + ref: 'v4.34.0' + commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + owner_id: 9919 + repo_id: 259445878 + 'goto-bus-stop/setup-zig@v2.0.0': + ref: 'v2.0.0' + commit: 'sha1-9566bb3e8749893055694249726756f25e099b30' + owner_id: 1006268 + repo_id: 212984112 + 'mlugg/setup-zig@v2.2.1': + ref: 'v2.2.1' + commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29' + owner_id: 7289241 + repo_id: 812112570 + 'oven-sh/setup-bun@v2.2.0': + ref: 'v2.2.0' + commit: 'sha1-0c5077e51419868618aeaa5fe8019c62421857d6' + owner_id: 108928776 + repo_id: 512644635 + 'peter-evans/repository-dispatch@v3.0.0': + ref: 'v3.0.0' + commit: 'sha1-ff45666b9427631e3450c54a1bcbee4d9ff4d7c0' + owner_id: 18365890 + repo_id: 220359305 + 'softprops/action-gh-release@v2.6.2': + ref: 'v2.6.2' + commit: 'sha1-3bb12739c298aeb8a4eeaf626c5b8d85266b0e65' + owner_id: 2242 + repo_id: 204253808 + 'sonarsource/sonarqube-scan-action@v8.1.0': + ref: 'v8.1.0' + commit: 'sha1-7006c4492b2e0ee0f816d36501671557c97f5995' + owner_id: 545988 + repo_id: 366408409 diff --git a/.github/workflows/backend-assurance.yml b/.github/workflows/backend-assurance.yml index 0b0c2c7d..4bdb33fb 100644 --- a/.github/workflows/backend-assurance.yml +++ b/.github/workflows/backend-assurance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Backend-Assurance Harness (epic #87 Tier C) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 0117e921..fc47f77a 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # SonarQube Cloud (SonarCloud) static analysis. Generated from the SonarCloud diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 45a32c1f..2f6b9bfb 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: @@ -44,12 +45,12 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Initialize CodeQL - uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3 + uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3 + uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/container-publish.yml b/.github/workflows/container-publish.yml index f5e3077e..fada542e 100644 --- a/.github/workflows/container-publish.yml +++ b/.github/workflows/container-publish.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Container Publish workflow — builds and pushes the container image to @@ -91,7 +92,7 @@ jobs: # gh attest verify oci://ghcr.io/${{ github.repository }}: \ # --repo ${{ github.repository }} - name: Attest container provenance - uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 + uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2.4.0 with: subject-name: ghcr.io/${{ github.repository }} subject-digest: ${{ steps.push.outputs.digest }} diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 5d2b2221..4a64d391 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index c3bdd5aa..8629be0e 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Full test suite for BoJ Server: E2E, aspect tests, and benchmarks. @@ -72,7 +73,7 @@ jobs: version: 0.16.0 - name: Install Deno - uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4 + uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4 with: deno-version: v2.x @@ -80,7 +81,7 @@ jobs: # tests/e2e_full.sh requires `mix` on PATH to start the Elixir # backend (elixir/ — `mix run --no-halt`). Pinned to match the # estate convention (see hypatia-scan.yml across the org). - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.18.2 + uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: '1.18' otp-version: '27' @@ -113,7 +114,7 @@ jobs: - name: Upload test logs if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: e2e-full-logs path: /tmp/boj-e2e-test.* @@ -182,7 +183,7 @@ jobs: - name: Upload benchmark results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: benchmark-results path: ffi/zig/zig-out/bench* @@ -232,7 +233,7 @@ jobs: - name: Install Deno if: matrix.runtime == 'deno' - uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4 + uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4 with: deno-version: v2.x @@ -279,7 +280,7 @@ jobs: - name: Upload bridge bench artifact if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 with: name: bench-bridge-results path: bench-bridge.txt @@ -290,7 +291,7 @@ jobs: # Advisory — a comment failure must never gate the bench job. # Same reasoning as the hypatia-scan PR-comment step. continue-on-error: true - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7 + uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 with: script: | const fs = require('fs'); diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml index 4fd44eac..f8437e05 100644 --- a/.github/workflows/fuzz.yml +++ b/.github/workflows/fuzz.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Fuzz testing for BoJ Server FFI layer # Addresses OpenSSF Scorecard "Fuzzing" check name: Fuzz Testing @@ -28,7 +29,7 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install Zig - uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2 + uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1 with: version: 0.16.0 diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index cc62f6c8..9ce3d89d 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # governance.yml — single wrapper calling the shared estate governance bundle # in hyperpolymath/standards instead of carrying per-repo copies. # diff --git a/.github/workflows/hcg-surface-drift.yml b/.github/workflows/hcg-surface-drift.yml index f4677497..0ea0eaa6 100644 --- a/.github/workflows/hcg-surface-drift.yml +++ b/.github/workflows/hcg-surface-drift.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # HCG Surface Drift Gate (standards#100 / standards#91 — Phase E §1.5) diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 44042905..fff3e08d 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Hypatia Neurosymbolic CI/CD Security Scan name: Hypatia Security Scan @@ -53,7 +54,7 @@ jobs: fetch-depth: 0 # Full history for better pattern analysis - name: Setup Elixir for Hypatia scanner - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.18.2 + uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 with: elixir-version: '1.18' otp-version: '27' @@ -243,7 +244,7 @@ jobs: always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.fork != true) - uses: github/codeql-action/upload-sarif@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1 + uses: github/codeql-action/upload-sarif@v4.32.6 with: sarif_file: hypatia.sarif # Distinct category so Hypatia results coexist with CodeQL's @@ -383,7 +384,7 @@ jobs: # the pull-requests: write permission above: a token/API hiccup or # a fork PR (read-only token) skips the comment, not the check. continue-on-error: true - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7 + uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 with: script: | const fs = require('fs'); diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index d52b810d..40388e10 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync @@ -26,7 +27,7 @@ jobs: timeout-minutes: 5 steps: - name: Trigger Propagation - uses: peter-evans/repository-dispatch@ff45666b9427631e3450c54a1bcbee4d9ff4d7c0 # v3 + uses: peter-evans/repository-dispatch@ff45666b9427631e3450c54a1bcbee4d9ff4d7c0 # v3.0.0 with: token: ${{ secrets.FARM_DISPATCH_TOKEN }} repository: hyperpolymath/.git-private-farm diff --git a/.github/workflows/lsp-dap-bsp.yml b/.github/workflows/lsp-dap-bsp.yml index 915cf9f8..e4e29669 100644 --- a/.github/workflows/lsp-dap-bsp.yml +++ b/.github/workflows/lsp-dap-bsp.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # lsp-dap-bsp.yml — Dedicated CI for Language Server, Debug Adapter, and Build Server cartridges # Validates ABI specs, FFI builds, adapter compilation, and panel manifests # for the three protocol cartridges (lsp-mcp, dap-mcp, bsp-mcp). diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 4d61c13b..0a4e1473 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: diff --git a/.github/workflows/pages-deploy.yml b/.github/workflows/pages-deploy.yml index 78eca2bd..230a0d3d 100644 --- a/.github/workflows/pages-deploy.yml +++ b/.github/workflows/pages-deploy.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Fallback Cloudflare Workers deploy via Direct Upload (wrangler deploy). # Bypasses the Cloudflare Git Integration build system entirely. # Uses wrangler deploy (Workers + Assets) rather than the deprecated @@ -19,7 +20,7 @@ jobs: deploy: runs-on: ubuntu-latest steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Deploy site/ to Cloudflare Workers (static assets) run: npx wrangler@latest deploy env: diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index 442dcdaa..497532df 100755 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # GitHub Pages docs deploy via the Ddraig SSG (#288). @@ -24,9 +25,9 @@ jobs: image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff steps: - name: Checkout Site - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 - name: Checkout Ddraig SSG - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 with: repository: hyperpolymath/ddraig-ssg path: .ddraig-ssg diff --git a/.github/workflows/proofs.yml b/.github/workflows/proofs.yml index 0942bd49..69f7dfe6 100644 --- a/.github/workflows/proofs.yml +++ b/.github/workflows/proofs.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Proofs Gate — type-check every Idris2 proof + enforce the trusted base. diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 2c9f32af..73460a76 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Publish workflow — publishes to npm and JSR on version tag push (v*). diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 112afd18..c0994aff 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by @@ -16,7 +17,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Send push notification email - uses: dawidd6/action-send-mail@6e502825a508b867ab2954ad6343b68787624c01 # pinned + uses: dawidd6/action-send-mail@2cea9617b09d79a095af21254fbcb7ae95903dde # v3.12.0 with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} diff --git a/.github/workflows/readme-derive.yml b/.github/workflows/readme-derive.yml index c5a89370..9103560a 100644 --- a/.github/workflows/readme-derive.yml +++ b/.github/workflows/readme-derive.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # README single-source derivation (ADR-004): README.adoc is canonical; # README.md is derived for the Glama MCP directory (Markdown-only renderer). # This caller delegates to the standards reusable, which reads the diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d888dbb0..d8b4876f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Release workflow — triggered by version tags (v*). @@ -28,7 +29,7 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install Zig - uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2 + uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1 with: version: 0.16.0 @@ -143,7 +144,7 @@ jobs: path: artifacts/ - name: Create GitHub Release - uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2 + uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2 with: body: ${{ needs.changelog.outputs.changelog }} draft: false diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 1e266ece..97c9baa6 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell # # Aligned with the documented caller pattern in diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 4839d606..fe54a678 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Secret Scanner on: diff --git a/.github/workflows/truthfulness.yml b/.github/workflows/truthfulness.yml index 9e8127f3..cf9f210d 100644 --- a/.github/workflows/truthfulness.yml +++ b/.github/workflows/truthfulness.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # Truthfulness invariant: the cartridge catalogue must never advertise as diff --git a/.github/workflows/zig-test.yml b/.github/workflows/zig-test.yml index 35c11edf..4a315ac1 100644 --- a/.github/workflows/zig-test.yml +++ b/.github/workflows/zig-test.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # BoJ Server — Zig FFI test & build pipeline @@ -65,7 +66,7 @@ jobs: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install Zig - uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2 + uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1 with: version: 0.16.0