Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 30 additions & 30 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ workflows:
'.github/workflows/agda-meta-checker.yml':
- 'actions/cache@v6.1.0'
- 'actions/checkout@v7.0.1'
- 'haskell-actions/setup@v2.11.0'
- 'haskell-actions/setup@v2.12.0'
'.github/workflows/boj-build.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/bridge-gate.yml':
Expand All @@ -24,10 +24,10 @@ workflows:
- 'actions/upload-artifact@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'mlugg/setup-zig@v2.2.1'
- 'swatinem/rust-cache@v2.9.1'
- 'swatinem/rust-cache@v2.9.2'
'.github/workflows/codeql.yml':
- 'actions/checkout@v7.0.1'
- 'github/codeql-action@v4.37.3'
- 'github/codeql-action@v4.37.7'
'.github/workflows/container-ci.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/dogfood-gate.yml':
Expand All @@ -37,11 +37,11 @@ workflows:
'.github/workflows/formal-verification.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'swatinem/rust-cache@v2.9.2'
'.github/workflows/generator-generic-ossf-slsa3-publish.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/ghcr-publish.yml':
- 'actions/attest-build-provenance@v4.1.1'
- 'actions/attest-build-provenance@v4.2.2'
- 'actions/checkout@v7.0.1'
'.github/workflows/governance.yml': []
'.github/workflows/hypatia-scan.yml': []
Expand All @@ -50,13 +50,13 @@ workflows:
'.github/workflows/live-provers.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'swatinem/rust-cache@v2.9.2'
'.github/workflows/mirror.yml': []
'.github/workflows/mvp-smoke.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'taiki-e/install-action@v2.85.3'
- 'swatinem/rust-cache@v2.9.2'
- 'taiki-e/install-action@v2.86.4'
'.github/workflows/pages.yml':
- 'actions/checkout@v7.0.1'
- 'actions/deploy-pages@v5.0.0'
Expand All @@ -65,31 +65,31 @@ workflows:
'.github/workflows/s4-loop.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'taiki-e/install-action@v2.85.3'
- 'swatinem/rust-cache@v2.9.2'
- 'taiki-e/install-action@v2.86.4'
'.github/workflows/scorecard.yml': []
'.github/workflows/secret-scanner.yml': []
'.github/workflows/security-scan.yml': []
'.github/workflows/server-boot-gate.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'swatinem/rust-cache@v2.9.2'
'.github/workflows/spark-theatre-gate.yml': []
'.github/workflows/verification-proofs-cron.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/workflow-linter.yml':
- 'actions/checkout@v7.0.1'
dependencies:
'actions/attest-build-provenance@v4.1.1':
ref: 'v4.1.1'
commit: 'sha1-0f67c3f4856b2e3261c31976d6725780e5e4c373'
'actions/attest-build-provenance@v4.2.2':
ref: 'v4.2.2'
commit: 'sha1-4d101475d8b20a2381f78447822ac1eab6504dd8'
owner_id: 44036562
repo_id: 760702757
uses:
- 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763'
'actions/attest@a1948c3f048ba23858d222213b7c278aabede763':
ref: 'v4.1.1'
commit: 'sha1-a1948c3f048ba23858d222213b7c278aabede763'
- 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d'
'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d':
ref: 'v4.2.1'
commit: 'sha1-508db95dd578ae2727ebd6217d5ba78e4fbda05d'
owner_id: 44036562
repo_id: 760701061
'actions/cache@v6.1.0':
Expand Down Expand Up @@ -134,33 +134,33 @@ dependencies:
commit: 'sha1-4360b52568e2003a75bf9bc1d59f33a8e3fc893c'
owner_id: 1940490
repo_id: 260749683
'github/codeql-action@v4.37.3':
ref: 'v4.37.3'
commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81'
'github/codeql-action@v4.37.7':
ref: 'v4.37.7'
commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
owner_id: 9919
repo_id: 259445878
'google/clusterfuzzlite@v1':
ref: 'v1'
commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1'
owner_id: 1342004
repo_id: 400046858
'haskell-actions/setup@v2.11.0':
ref: 'v2.11.0'
commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553'
'haskell-actions/setup@v2.12.0':
ref: 'v2.12.0'
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
owner_id: 75048950
repo_id: 623796603
'mlugg/setup-zig@v2.2.1':
ref: 'v2.2.1'
commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29'
owner_id: 7289241
repo_id: 812112570
'swatinem/rust-cache@v2.9.1':
ref: 'v2.9.1'
commit: 'sha1-c19371144df3bb44fab255c43d04cbc2ab54d1c4'
'swatinem/rust-cache@v2.9.2':
ref: 'v2.9.2'
commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
owner_id: 580492
repo_id: 298565987
'taiki-e/install-action@v2.85.3':
ref: 'v2.85.3'
commit: 'sha1-18b1216eba7f8039b0f8d131d5473787f0edce68'
'taiki-e/install-action@v2.86.4':
ref: 'v2.86.4'
commit: 'sha1-a2a5f6e99e1a31540baa0468acfa302cff0f359f'
owner_id: 43724913
repo_id: 442947557
1 change: 1 addition & 0 deletions .github/workflows/agda-meta-checker.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# CI workflow for ECHIDNA Agda meta-checker
# Type-checks all formal proofs verifying trust pipeline correctness

Expand Down
1 change: 1 addition & 0 deletions .github/workflows/boj-build.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: BoJ Server Build Trigger
on:
push:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/bridge-gate.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
#
# bridge-gate.yml -- merge-orchestration CVE/bump gate.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/cargo-audit.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
# cargo-audit.yml — Dependency vulnerability scanning for Rust projects.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/cflite_batch.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: ClusterFuzzLite batch fuzzing
on:
schedule:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/cflite_pr.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: ClusterFuzzLite PR fuzzing
on:
pull_request:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/chapel-ci.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Chapel Accelerator CI

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: CodeQL Security Analysis

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/container-ci.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
#
# container-ci.yml — Container build verification.
#
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/dogfood-gate.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
# dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/dogfood-proofs-ci.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Gates the ECHIDNA dogfood proof corpus: every theorem under proofs/{coq,lean,agda}
# must type-check. These proofs had no CI coverage before this workflow -- the other
# proof workflows are path-filtered to meta-checker/** (agda-meta-checker) and
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/formal-verification.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
# formal-verification.yml — Creusot formal verification of the trust-pipeline kernel.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/generator-generic-ossf-slsa3-publish.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# This workflow uses actions that are not certified by GitHub.
# They are provided by a third-party and are governed by
# separate terms of service, privacy policy, and support
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/ghcr-publish.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Publish to GHCR

permissions:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/governance.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Governance

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Hypatia Security Scan

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/idris2-abi-ci.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Idris2 ABI Type-Check

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/live-provers.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# ECHIDNA — Live-Prover CI
#
# Exercises real prover binaries against canonical micro-goals. Complements
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/mirror.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Mirror to Git Forges

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/mvp-smoke.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: MVP Smoke (Best Effort)

on:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: GitHub Pages (Ddraig SSG)
on:
push:
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/rust-ci.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Rust CI — thin wrapper calling the shared estate reusable in
# hyperpolymath/standards. Configure once, propagate everywhere.
# See: docs/CI-REUSABLE-WORKFLOWS.adoc in standards.
Expand All @@ -11,6 +12,7 @@ on:
pull_request:

permissions:
actions: read
contents: read

jobs:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/s4-loop.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# S4 loop-closure CI — brings up verisim-api as a service container and
# runs the echidna s4_loop_closure integration test. Filed once
# ghcr.io/hyperpolymath/verisimdb-api:latest became available (PR #121).
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: OSSF Scorecard

on:
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/secret-scanner.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
name: Secret Scanner

on:
Expand All @@ -12,12 +13,13 @@ concurrency:
cancel-in-progress: true

permissions:
actions: read
contents: read

jobs:
scan:
# caller must grant at least that or the run startup-fails.
permissions:
contents: read
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570)
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570)
secrets: inherit
1 change: 1 addition & 0 deletions .github/workflows/security-scan.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.

name: Security Scan

Expand Down
1 change: 1 addition & 0 deletions .github/workflows/server-boot-gate.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Server boot gate — builds the echidna binary, boots the server, and
# verifies that /api/health, /api/provers, and a session {id} route all
# respond. Exists so "compiles" can never again mean "boots" — the
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/spark-theatre-gate.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Estate SPARK Theatre Gate — thin caller of the reusable workflow in
# hyperpolymath/standards (#135 / #141). Pinned by commit SHA per the
# estate action-pinning policy. Regenerate the pin only when the reusable
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/verification-proofs-cron.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Weekly verification of the heavier self-proof corpora that are too slow and too
# network-heavy to gate on every PR: currently Isabelle/HOL (proofs/isabelle). The
# Isabelle toolchain is a large, non-apt download (~500MB tarball), so this runs on
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/workflow-linter.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: AGPL-3.0-or-later
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# Prevention workflow - validates all workflows have proper security config
name: Workflow Security Linter

Expand Down
Loading