Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 20 additions & 20 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -5,15 +5,7 @@ version: 'v0.0.2'
workflows:
'.github/workflows/affinescript-verify.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'ocaml/setup-ocaml@v3.7.1'
'.github/workflows/changelog.yml': []
'.github/workflows/codeql.yml': []
'.github/workflows/deno-ci.yml': []
'.github/workflows/elixir-ci.yml': []
'.github/workflows/governance.yml': []
'.github/workflows/hypatia-scan.yml': []
'.github/workflows/mirror.yml': []
'.github/workflows/readme-derive.yml': []
- 'ocaml/setup-ocaml@605a7e998e76e035b82c14d618a6e1010732c4ce'
'.github/workflows/boj-build.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/casket-pages.yml':
Expand All @@ -22,17 +14,20 @@ workflows:
- 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d'
- 'actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128'
- 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9'
- 'haskell-actions/setup@v2.12.0'
- 'haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d'
'.github/workflows/changelog-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/changelog.yml': []
'.github/workflows/codeql-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'github/codeql-action@v4.37.7'
- 'github/codeql-action@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
'.github/workflows/codeql.yml': []
'.github/workflows/debt-measure.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/deno-ci-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
'.github/workflows/deno-ci.yml': []
'.github/workflows/doc-format.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/dyadt-verify.yml':
Expand All @@ -45,18 +40,21 @@ workflows:
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
'.github/workflows/elixir-ci.yml': []
'.github/workflows/governance-reusable.yml':
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
- 'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
'.github/workflows/governance.yml': []
'.github/workflows/hypatia-scan-reusable.yml':
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
- 'github/codeql-action@v4.37.7'
- 'github/codeql-action@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
'.github/workflows/hypatia-scan.yml': []
'.github/workflows/instant-sync.yml':
- 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697'
'.github/workflows/launcher-standard-lockstep.yml':
Expand All @@ -65,8 +63,9 @@ workflows:
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/mirror-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'dtolnay/rust-toolchain@v1'
- 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
- 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555'
'.github/workflows/mirror.yml': []
'.github/workflows/no-js-scan.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/pages.yml':
Expand All @@ -75,12 +74,13 @@ workflows:
- 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9'
'.github/workflows/readme-derive-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/readme-derive.yml': []
'.github/workflows/registry-verify.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/rust-ci-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'dtolnay/rust-toolchain@v1'
- 'swatinem/rust-cache@v2.9.2'
- 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
- 'swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
'.github/workflows/scorecard-enforcer.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
Expand Down Expand Up @@ -165,7 +165,7 @@ dependencies:
commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
owner_id: 42048915
repo_id: 356423100
'dtolnay/rust-toolchain@v1':
'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772':
ref: 'v1'
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
owner_id: 1940490
Expand All @@ -180,17 +180,17 @@ dependencies:
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
owner_id: 47606891
repo_id: 331103973
'github/codeql-action@v4.37.7':
'github/codeql-action@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd':
ref: 'v4.37.7'
commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
owner_id: 9919
repo_id: 259445878
'haskell-actions/setup@v2.12.0':
'haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d':
ref: 'v2.12.0'
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
owner_id: 75048950
repo_id: 623796603
'ocaml/setup-ocaml@v3.7.1':
'ocaml/setup-ocaml@605a7e998e76e035b82c14d618a6e1010732c4ce':
ref: 'v3.7.1'
commit: 'sha1-605a7e998e76e035b82c14d618a6e1010732c4ce'
owner_id: 1841483
Expand All @@ -205,7 +205,7 @@ dependencies:
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'
owner_id: 18365890
repo_id: 220359305
'swatinem/rust-cache@v2.9.2':
'swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6':
ref: 'v2.9.2'
commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
owner_id: 580492
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/affinescript-verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,6 @@ jobs:
timeout-minutes: 20
name: AffineScript Verify
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
steps:
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/boj-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,6 @@ jobs:
trigger-boj:
name: Trigger BoJ server
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 10
# No job-level gate: the `secrets` context is not available in `if:`
# (referencing it is an "Unrecognized named-value: 'secrets'" startup
Expand Down Expand Up @@ -71,7 +70,6 @@ jobs:
name: K9-SVC contractile validation
timeout-minutes: 10
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/casket-pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,6 @@ jobs:
build:
timeout-minutes: 20
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
Expand Down Expand Up @@ -96,7 +95,6 @@ jobs:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
timeout-minutes: 30
needs: build
steps:
- name: Deploy to GitHub Pages
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/debt-measure.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,6 @@ jobs:
measure:
name: Measure and record
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 15
permissions:
contents: write
Expand Down
20 changes: 17 additions & 3 deletions .github/workflows/deno-ci-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,16 +104,30 @@ jobs:
if: steps.detect.outputs.has_targets == 'true' || steps.detect.outputs.has_config == 'true'
run: deno fmt --check

- name: Deno test
if: steps.detect.outputs.has_tests == 'true'
- name: Deno test (configured package)
# A config may intentionally own no tests yet. --permit-no-files keeps
# that honest scope green without discovering tests in nested products.
# Avoid requesting a coverage report for an explicitly empty scope:
# Deno prints "Error generating coverage report" even though it exits 0.
if: steps.detect.outputs.has_config == 'true'
run: deno test --allow-all --permit-no-files

- name: Deno test (configless fallback)
if: steps.detect.outputs.has_config == 'false' && steps.detect.outputs.has_tests == 'true'
run: deno test --allow-all --coverage=coverage

- name: Deno type check
if: steps.detect.outputs.has_targets == 'true'
# Soft-pass: `deno check` exits non-zero on unresolved imports we
# don't yet require contributors to vendor. We surface output for
# diagnostics but don't fail the gate.
run: deno check . || echo "::warning::deno check reported issues (non-blocking)."
run: |
if [ "${{ steps.detect.outputs.has_config }}" = "true" ] \
&& deno task 2>/dev/null | grep -q '^ci:check'; then
deno task ci:check
else
deno check . || echo "::warning::deno check reported issues (non-blocking)."
fi

- name: Summary
run: |
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/doc-format.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,6 @@ jobs:
timeout-minutes: 10
name: Check Documentation Format
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/dyadt-verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,6 @@ jobs:
verify-claims:
name: Verify CLAIMS.a2ml + conformance
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 10
steps:
- name: Checkout repository
Expand Down
4 changes: 0 additions & 4 deletions .github/workflows/echidna-verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,6 @@ jobs:
agda-lol:
name: Agda — lol/proofs
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 20
steps:
- name: Checkout
Expand Down Expand Up @@ -88,7 +87,6 @@ jobs:
idris2-a2ml:
name: Idris2 — a2ml proofs
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 20
steps:
- name: Checkout
Expand Down Expand Up @@ -157,7 +155,6 @@ jobs:
idris2-avow:
name: Idris2 — AVOW consent proofs
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 20
steps:
- name: Checkout
Expand Down Expand Up @@ -227,7 +224,6 @@ jobs:
name: Trust pipeline summary
needs: [agda-lol, idris2-a2ml, idris2-avow]
runs-on: ubuntu-latest
timeout-minutes: 30
if: always()
steps:
- name: Summarise
Expand Down
24 changes: 12 additions & 12 deletions .github/workflows/governance-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1085,25 +1085,25 @@ jobs:
GH_TOKEN: ${{ github.token }}
run: |
if [ -f .github/workflows/actions.lock ]; then
# Lockfile repos: pin authority is actions.lock (the runner
# enforces it), so tag-style refs are legitimate. Verify every
# action ref has a lockfile entry instead of grepping for SHAs.
# The lockfile records transitive dependency evidence, while direct
# workflow references remain visibly SHA-pinned. Keep both layers:
# external analysers and GitHub's sha_pinning_required setting do
# not infer direct pins from actions.lock.
gh extension install github/gh-actions-lock
gh actions-lock --verify-local
# Cross-repo reusable calls stay outside lockfile scope and must
# remain SHA-pinned inline (standards' own calls exempted, as in
# the grep below).
unpinned=$(grep -rnE "^[[:space:]]+uses:[[:space:]]*[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+/\.github/workflows/[^@]+@" .github/workflows/ | \
bash scripts/update-actions-lock.sh --verify-local
unpinned=$(grep -rnE --include='*.yml' --include='*.yaml' \
"^[[:space:]]+uses:" .github/workflows/ | \
grep -v "@[a-f0-9]\{40\}" | \
grep -v "uses: hyperpolymath/standards/" || true)
grep -v "uses: \./\|uses: docker://\|uses: hyperpolymath/standards/" || true)
if [ -n "$unpinned" ]; then
echo "ERROR: reusable workflow calls not SHA-pinned:"
echo "ERROR: direct workflow references not SHA-pinned:"
echo "$unpinned"
exit 1
fi
echo "Lockfile coverage verified; reusable calls SHA-pinned"
echo "Lockfile coverage verified; direct references SHA-pinned"
else
unpinned=$(grep -rnE "^[[:space:]]+uses:" .github/workflows/ | \
unpinned=$(grep -rnE --include='*.yml' --include='*.yaml' \
"^[[:space:]]+uses:" .github/workflows/ | \
grep -v "@[a-f0-9]\{40\}" | \
grep -v "uses: \./\|uses: docker://\|uses: actions/github-script\|uses: hyperpolymath/standards/" || true)
if [ -n "$unpinned" ]; then
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/instant-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,6 @@ jobs:
dispatch:
timeout-minutes: 10
runs-on: ubuntu-latest
timeout-minutes: 30
# Map the secret to env so step `if:`s can gate on its presence: the
# `secrets` context is NOT available in `if:` (using it is an
# "Unrecognized named-value: 'secrets'" startup failure). `env` IS
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/launcher-standard-lockstep.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,6 @@ jobs:
timeout-minutes: 10
name: Verify launcher-standard lock-step
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout (full history for base/head diff)
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/makefile-blocker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,6 @@ jobs:
timeout-minutes: 10
name: Block Makefile Changes
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/no-js-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@ jobs:
timeout-minutes: 10
name: Scan for hand-authored JavaScript/TypeScript
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,6 @@ concurrency:
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 15
container:
image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff
Expand Down Expand Up @@ -49,7 +48,6 @@ jobs:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 15
needs: build
steps:
Expand Down
5 changes: 2 additions & 3 deletions .github/workflows/registry-verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,6 @@ jobs:
verify:
name: Registry + topology in sync
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 10
steps:
- name: Checkout repository
Expand Down Expand Up @@ -63,7 +62,7 @@ jobs:
echo ""
echo '```sh'
echo "just registry # or: bash scripts/build-registry.sh"
echo "git add .machine_readable/REGISTRY.a2ml TOPOLOGY.md"
echo "git add .machine_readable/REGISTRY.a2ml TOPOLOGY.adoc"
echo '```'
echo ""
echo "Install the pre-commit guard so this is caught before push:"
Expand Down Expand Up @@ -91,7 +90,7 @@ jobs:
{
echo "### Compliance dashboard drift"
echo ""
echo "COMPLIANCE-DASHBOARD.md is stale, a scorecard is malformed/orphaned,"
echo "COMPLIANCE-DASHBOARD.adoc is stale, a scorecard is malformed/orphaned,"
echo "or a registered spec has no scorecard. Fix locally:"
echo ""
echo '```sh'
Expand Down
3 changes: 0 additions & 3 deletions .github/workflows/scorecard-enforcer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,6 @@ permissions:
jobs:
scorecard:
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 15
permissions:
security-events: write
Expand All @@ -43,7 +42,6 @@ jobs:
check-score:
needs: scorecard
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 10
steps:
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
Expand All @@ -67,7 +65,6 @@ jobs:

check-critical:
runs-on: ubuntu-latest
timeout-minutes: 30
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
Loading
Loading