Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
154 changes: 154 additions & 0 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
@@ -0,0 +1,154 @@
# This file is machine-generated by `gh actions-lock`.
# Do not edit by hand; run `gh actions-lock` to update.
# Docs: https://gh.io/actions-lockfile
version: 'v0.0.2'
workflows:
'.github/workflows/governance.yml': []
'.github/workflows/hypatia-scan.yml': []
'.github/workflows/mirror.yml': []
'.github/workflows/scorecard.yml': []
'.github/workflows/secret-scanner.yml': []
'.github/workflows/spark-theatre-gate.yml': []
'.github/workflows/boj-build.yml':
- 'actions/checkout@v4.1.7'
'.github/workflows/casket-pages.yml':
- 'actions/cache@v4.3.0'
- 'actions/checkout@v4.1.1'
- 'actions/configure-pages@v5.0.0'
- 'actions/deploy-pages@v4.0.5'
- 'actions/upload-artifact@v4.6.2'
- 'haskell-actions/setup@v2.7.5'
'.github/workflows/cflite_batch.yml':
- 'google/clusterfuzzlite@v1'
'.github/workflows/cflite_pr.yml':
- 'google/clusterfuzzlite@v1'
'.github/workflows/ci.yml':
- 'actions/checkout@v4.3.1'
'.github/workflows/codeql.yml':
- 'actions/checkout@v6.0.2'
- 'github/codeql-action@v4.34.0'
'.github/workflows/dependabot-automerge.yml':
- 'dependabot/fetch-metadata@v2.2.0'
'.github/workflows/dogfood-gate.yml':
- 'actions/checkout@v4.3.1'
- 'hyperpolymath/a2ml-ecosystem@main'
- 'hyperpolymath/k9-ecosystem@main'
'.github/workflows/finishingbot.yml':
- 'actions/checkout@v4.1.1'
- 'actions/upload-artifact@v4.1.0'
- 'dtolnay/rust-toolchain@v1'
- 'swatinem/rust-cache@v2.7.8'
'.github/workflows/glambot.yml':
- 'actions/checkout@v4.1.1'
'.github/workflows/instant-sync.yml':
- 'peter-evans/repository-dispatch@v3.0.0'
'.github/workflows/push-email-notify.yml':
- 'dawidd6/action-send-mail@v3.12.0'
'.github/workflows/rhodibot.yml':
- 'actions/checkout@v4.1.1'
- 'actions/upload-artifact@v4.1.0'
- 'dtolnay/rust-toolchain@v1'
- 'swatinem/rust-cache@v2.7.8'
'.github/workflows/seambot.yml':
- 'actions/checkout@v4.1.1'
- 'actions/upload-artifact@v4.1.0'
- 'dtolnay/rust-toolchain@v1'
- 'swatinem/rust-cache@v2.7.8'
'.github/workflows/workflow-linter.yml':
- 'actions/checkout@v4.1.1'
dependencies:
'actions/cache@v4.3.0':
ref: 'v4.3.0'
commit: 'sha1-0057852bfaa89a56745cba8c7296529d2fc39830'
owner_id: 44036562
repo_id: 215566462
'actions/checkout@v4.1.1':
ref: 'v4.1.1'
commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11'
owner_id: 44036562
repo_id: 197814629
'actions/checkout@v4.1.7':
ref: 'v4.1.7'
commit: 'sha1-692973e3d937129bcbf40652eb9f2f61becf3332'
owner_id: 44036562
repo_id: 197814629
'actions/checkout@v4.3.1':
ref: 'v4.3.1'
commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5'
owner_id: 44036562
repo_id: 197814629
'actions/checkout@v6.0.2':
ref: 'v6.0.2'
commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd'
owner_id: 44036562
repo_id: 197814629
'actions/configure-pages@v5.0.0':
ref: 'v5.0.0'
commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b'
owner_id: 44036562
repo_id: 513659658
'actions/deploy-pages@v4.0.5':
ref: 'v4.0.5'
commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e'
owner_id: 44036562
repo_id: 438112499
'actions/upload-artifact@v4.1.0':
ref: 'v4.1.0'
commit: 'sha1-1eb3cb2b3e0f29609092a73eb033bb759a334595'
owner_id: 44036562
repo_id: 192625955
'actions/upload-artifact@v4.6.2':
ref: 'v4.6.2'
commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02'
owner_id: 44036562
repo_id: 192625955
'dawidd6/action-send-mail@v3.12.0':
ref: 'v3.12.0'
commit: 'sha1-6e502825a508b867ab2954ad6343b68787624c01'
owner_id: 9713907
repo_id: 222439721
'dependabot/fetch-metadata@v2.2.0':
ref: 'v2.2.0'
commit: 'sha1-dbb049abf0d677abbd7f7eee0375145b417fdd34'
owner_id: 27347476
repo_id: 371068214
'dtolnay/rust-toolchain@v1':
ref: 'v1'
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
owner_id: 1940490
repo_id: 260749683
'github/codeql-action@v4.34.0':
ref: 'v4.34.0'
commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745'
owner_id: 9919
repo_id: 259445878
'google/clusterfuzzlite@v1':
ref: 'v1'
commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1'
owner_id: 1342004
repo_id: 400046858
'haskell-actions/setup@v2.7.5':
ref: 'v2.7.5'
commit: 'sha1-ec49483bfc012387b227434aba94f59a6ecd0900'
owner_id: 75048950
repo_id: 623796603
'hyperpolymath/a2ml-ecosystem@main':
ref: 'main'
commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79'
owner_id: 6759885
repo_id: 1275649586
'hyperpolymath/k9-ecosystem@main':
ref: 'main'
commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562'
owner_id: 6759885
repo_id: 1275650185
'peter-evans/repository-dispatch@v3.0.0':
ref: 'v3.0.0'
commit: 'sha1-ff45666b9427631e3450c54a1bcbee4d9ff4d7c0'
owner_id: 18365890
repo_id: 220359305
'swatinem/rust-cache@v2.7.8':
ref: 'v2.7.8'
commit: 'sha1-9d47c6ad4b02e050fd481d890b2ea34778fd09d6'
owner_id: 580492
repo_id: 298565987
3 changes: 2 additions & 1 deletion .github/workflows/boj-build.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: BoJ Server Build Trigger
on:
push:
Expand All @@ -9,7 +10,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
uses: actions/checkout@v4.1.7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 MEDIUM RISK

This change replaces a pinned commit SHA with a mutable version tag. This reduces security (as tags can be moved) and violates the project's policy of pinning actions with SHAs. Revert to the action@SHA # version format to comply with the local security linter.

- name: Trigger BoJ Server (Casket/ssg-mcp)
run: |
# Send a secure trigger to boj-server to build this repository
Expand Down
15 changes: 8 additions & 7 deletions .github/workflows/casket-pages.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: GitHub Pages

on:
Expand All @@ -21,22 +22,22 @@
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1

- name: Checkout casket-ssg
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
uses: actions/checkout@v4.1.1
with:
repository: hyperpolymath/casket-ssg
path: .casket-ssg

- name: Setup GHCup
uses: haskell-actions/setup@ec49483bfc012387b227434aba94f59a6ecd0900 # v2
uses: haskell-actions/setup@v2.7.5

Check failure on line 34 in .github/workflows/casket-pages.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_ubicity&issues=AaBCyC8XWEWckQVeGEP2&open=AaBCyC8XWEWckQVeGEP2&pullRequest=109

Check warning on line 34 in .github/workflows/casket-pages.yml

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

.github/workflows/casket-pages.yml#L34

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.
with:
ghc-version: '9.8.2'
cabal-version: '3.10'

- name: Cache Cabal
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
uses: actions/cache@v4.3.0
with:
path: |
~/.cabal/packages
Expand Down Expand Up @@ -98,7 +99,7 @@
touch ../_site/.nojekyll

- name: Setup Pages
uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5
uses: actions/configure-pages@v5.0.0

# NOTE: actions/upload-pages-artifact is a composite that internally
# calls actions/upload-artifact@v4 (an UNPINNED upstream tag). The
Expand All @@ -117,7 +118,7 @@
--exclude=.git --exclude=.github \
.
- name: Upload artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@v4.6.2
with:
name: github-pages
path: ${{ runner.temp }}/artifact.tar
Expand All @@ -133,4 +134,4 @@
steps:
- name: Deploy to GitHub Pages
id: deployment
uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4
uses: actions/deploy-pages@v4.0.5
5 changes: 3 additions & 2 deletions .github/workflows/cflite_batch.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: ClusterFuzzLite batch fuzzing
on:
schedule:
Expand All @@ -23,14 +24,14 @@
steps:
- name: Build Fuzzers (${{ matrix.sanitizer }})
id: build
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/build_fuzzers@v1

Check failure on line 27 in .github/workflows/cflite_batch.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_ubicity&issues=AaBCyC_ZWEWckQVeGEP9&open=AaBCyC_ZWEWckQVeGEP9&pullRequest=109

Check warning on line 27 in .github/workflows/cflite_batch.yml

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

.github/workflows/cflite_batch.yml#L27

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.
with:
language: rust
sanitizer: ${{ matrix.sanitizer }}

- name: Run Fuzzers (${{ matrix.sanitizer }})
id: run
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/run_fuzzers@v1

Check failure on line 34 in .github/workflows/cflite_batch.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_ubicity&issues=AaBCyC_ZWEWckQVeGEP-&open=AaBCyC_ZWEWckQVeGEP-&pullRequest=109

Check warning on line 34 in .github/workflows/cflite_batch.yml

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

.github/workflows/cflite_batch.yml#L34

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 1800
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/cflite_pr.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: ClusterFuzzLite PR fuzzing
on:
pull_request:
Expand All @@ -24,14 +25,14 @@
steps:
- name: Build Fuzzers (${{ matrix.sanitizer }})
id: build
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/build_fuzzers@v1

Check failure on line 28 in .github/workflows/cflite_pr.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_ubicity&issues=AaBCyDAkWEWckQVeGEQC&open=AaBCyDAkWEWckQVeGEQC&pullRequest=109

Check warning on line 28 in .github/workflows/cflite_pr.yml

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

.github/workflows/cflite_pr.yml#L28

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.
with:
language: rust
sanitizer: ${{ matrix.sanitizer }}

- name: Run Fuzzers (${{ matrix.sanitizer }})
id: run
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/run_fuzzers@v1

Check failure on line 35 in .github/workflows/cflite_pr.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_ubicity&issues=AaBCyDAkWEWckQVeGEQD&open=AaBCyDAkWEWckQVeGEQD&pullRequest=109

Check warning on line 35 in .github/workflows/cflite_pr.yml

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

.github/workflows/cflite_pr.yml#L35

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 300
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: CI

on:
Expand All @@ -19,7 +20,7 @@ jobs:

steps:
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
uses: actions/checkout@v4.3.1

- name: Install Idris2 0.8.0
env:
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: CodeQL Security Analysis

on:
Expand Down Expand Up @@ -36,15 +37,15 @@ jobs:

steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@v6.0.2

- name: Initialize CodeQL
uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3
uses: github/codeql-action/init@v4.34.0
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3
uses: github/codeql-action/analyze@v4.34.0
with:
category: "/language:${{ matrix.language }}"
3 changes: 2 additions & 1 deletion .github/workflows/dependabot-automerge.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
#
# dependabot-automerge.yml — enable GitHub's native auto-merge on
# Dependabot pull requests that match a declared severity / ecosystem
Expand Down Expand Up @@ -55,7 +56,7 @@
steps:
- name: Fetch Dependabot metadata
id: meta
uses: dependabot/fetch-metadata@dbb049abf0d677abbd7f7eee0375145b417fdd34 # v2.2.0
uses: dependabot/fetch-metadata@v2.2.0

Check failure on line 59 in .github/workflows/dependabot-automerge.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_ubicity&issues=AaBCyC_rWEWckQVeGEP_&open=AaBCyC_rWEWckQVeGEP_&pullRequest=109

Check warning on line 59 in .github/workflows/dependabot-automerge.yml

View check run for this annotation

Codacy Production / Codacy Static Code Analysis

.github/workflows/dependabot-automerge.yml#L59

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 HIGH RISK

Avoid removing the commit SHA when updating actions. Pinning to a full-length commit SHA is the only way to ensure the action used is immutable and protected against upstream tampering.

Suggested change
uses: dependabot/fetch-metadata@v2.2.0
uses: dependabot/fetch-metadata@dbb049abf0d677abbd7f7eee0375145b417fdd34 # v2.2.0

See Issue in Codacy

with:
github-token: ${{ secrets.GITHUB_TOKEN }}

Expand Down
Loading
Loading