diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 755963a3..883b0dfc 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -6,7 +6,7 @@ workflows: '.github/workflows/agda-meta-checker.yml': - 'actions/cache@v6.1.0' - 'actions/checkout@v7.0.1' - - 'haskell-actions/setup@v2.11.0' + - 'haskell-actions/setup@v2.12.0' '.github/workflows/boj-build.yml': - 'actions/checkout@v7.0.1' '.github/workflows/bridge-gate.yml': @@ -24,10 +24,10 @@ workflows: - 'actions/upload-artifact@v7.0.1' - 'dtolnay/rust-toolchain@stable' - 'mlugg/setup-zig@v2.2.1' - - 'swatinem/rust-cache@v2.9.1' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.37.3' + - 'github/codeql-action@v4.37.7' '.github/workflows/container-ci.yml': - 'actions/checkout@v7.0.1' '.github/workflows/dogfood-gate.yml': @@ -37,11 +37,11 @@ workflows: '.github/workflows/formal-verification.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - - 'swatinem/rust-cache@v2.9.1' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/generator-generic-ossf-slsa3-publish.yml': - 'actions/checkout@v7.0.1' '.github/workflows/ghcr-publish.yml': - - 'actions/attest-build-provenance@v4.1.1' + - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': [] @@ -50,13 +50,13 @@ workflows: '.github/workflows/live-provers.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - - 'swatinem/rust-cache@v2.9.1' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/mirror.yml': [] '.github/workflows/mvp-smoke.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - - 'swatinem/rust-cache@v2.9.1' - - 'taiki-e/install-action@v2.85.3' + - 'swatinem/rust-cache@v2.9.2' + - 'taiki-e/install-action@v2.86.4' '.github/workflows/pages.yml': - 'actions/checkout@v7.0.1' - 'actions/deploy-pages@v5.0.0' @@ -65,31 +65,31 @@ workflows: '.github/workflows/s4-loop.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - - 'swatinem/rust-cache@v2.9.1' - - 'taiki-e/install-action@v2.85.3' + - 'swatinem/rust-cache@v2.9.2' + - 'taiki-e/install-action@v2.86.4' '.github/workflows/scorecard.yml': [] '.github/workflows/secret-scanner.yml': [] '.github/workflows/security-scan.yml': [] '.github/workflows/server-boot-gate.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - - 'swatinem/rust-cache@v2.9.1' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/spark-theatre-gate.yml': [] '.github/workflows/verification-proofs-cron.yml': - 'actions/checkout@v7.0.1' '.github/workflows/workflow-linter.yml': - 'actions/checkout@v7.0.1' dependencies: - 'actions/attest-build-provenance@v4.1.1': - ref: 'v4.1.1' - commit: 'sha1-0f67c3f4856b2e3261c31976d6725780e5e4c373' + 'actions/attest-build-provenance@v4.2.2': + ref: 'v4.2.2' + commit: 'sha1-4d101475d8b20a2381f78447822ac1eab6504dd8' owner_id: 44036562 repo_id: 760702757 uses: - - 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763' - 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763': - ref: 'v4.1.1' - commit: 'sha1-a1948c3f048ba23858d222213b7c278aabede763' + - 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d' + 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d': + ref: 'v4.2.1' + commit: 'sha1-508db95dd578ae2727ebd6217d5ba78e4fbda05d' owner_id: 44036562 repo_id: 760701061 'actions/cache@v6.1.0': @@ -134,9 +134,9 @@ dependencies: commit: 'sha1-4360b52568e2003a75bf9bc1d59f33a8e3fc893c' owner_id: 1940490 repo_id: 260749683 - 'github/codeql-action@v4.37.3': - ref: 'v4.37.3' - commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81' + 'github/codeql-action@v4.37.7': + ref: 'v4.37.7' + commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd' owner_id: 9919 repo_id: 259445878 'google/clusterfuzzlite@v1': @@ -144,9 +144,9 @@ dependencies: commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1' owner_id: 1342004 repo_id: 400046858 - 'haskell-actions/setup@v2.11.0': - ref: 'v2.11.0' - commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553' + 'haskell-actions/setup@v2.12.0': + ref: 'v2.12.0' + commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d' owner_id: 75048950 repo_id: 623796603 'mlugg/setup-zig@v2.2.1': @@ -154,13 +154,13 @@ dependencies: commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29' owner_id: 7289241 repo_id: 812112570 - 'swatinem/rust-cache@v2.9.1': - ref: 'v2.9.1' - commit: 'sha1-c19371144df3bb44fab255c43d04cbc2ab54d1c4' + 'swatinem/rust-cache@v2.9.2': + ref: 'v2.9.2' + commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6' owner_id: 580492 repo_id: 298565987 - 'taiki-e/install-action@v2.85.3': - ref: 'v2.85.3' - commit: 'sha1-18b1216eba7f8039b0f8d131d5473787f0edce68' + 'taiki-e/install-action@v2.86.4': + ref: 'v2.86.4' + commit: 'sha1-a2a5f6e99e1a31540baa0468acfa302cff0f359f' owner_id: 43724913 repo_id: 442947557 diff --git a/.github/workflows/agda-meta-checker.yml b/.github/workflows/agda-meta-checker.yml index c907d1b0..8a32aca5 100644 --- a/.github/workflows/agda-meta-checker.yml +++ b/.github/workflows/agda-meta-checker.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # CI workflow for ECHIDNA Agda meta-checker # Type-checks all formal proofs verifying trust pipeline correctness diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 1445eb6f..d2c956d4 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: BoJ Server Build Trigger on: push: diff --git a/.github/workflows/bridge-gate.yml b/.github/workflows/bridge-gate.yml index ce2cd1ff..2e65025a 100644 --- a/.github/workflows/bridge-gate.yml +++ b/.github/workflows/bridge-gate.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell # # bridge-gate.yml -- merge-orchestration CVE/bump gate. diff --git a/.github/workflows/cargo-audit.yml b/.github/workflows/cargo-audit.yml index 26299f4d..937fed86 100644 --- a/.github/workflows/cargo-audit.yml +++ b/.github/workflows/cargo-audit.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # cargo-audit.yml — Dependency vulnerability scanning for Rust projects. diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index 35167d47..c6ecee72 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: ClusterFuzzLite batch fuzzing on: schedule: diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index 975a7e5e..656ba57c 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: ClusterFuzzLite PR fuzzing on: pull_request: diff --git a/.github/workflows/chapel-ci.yml b/.github/workflows/chapel-ci.yml index c23c794f..9147d7a6 100644 --- a/.github/workflows/chapel-ci.yml +++ b/.github/workflows/chapel-ci.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Chapel Accelerator CI on: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index a09eb41d..4554278c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: diff --git a/.github/workflows/container-ci.yml b/.github/workflows/container-ci.yml index 1c81f5d1..4df1a280 100644 --- a/.github/workflows/container-ci.yml +++ b/.github/workflows/container-ci.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # # container-ci.yml — Container build verification. # diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 1702341c..74c1ee4e 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate diff --git a/.github/workflows/dogfood-proofs-ci.yml b/.github/workflows/dogfood-proofs-ci.yml index c7f492db..5e367e50 100644 --- a/.github/workflows/dogfood-proofs-ci.yml +++ b/.github/workflows/dogfood-proofs-ci.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Gates the ECHIDNA dogfood proof corpus: every theorem under proofs/{coq,lean,agda} # must type-check. These proofs had no CI coverage before this workflow -- the other # proof workflows are path-filtered to meta-checker/** (agda-meta-checker) and diff --git a/.github/workflows/formal-verification.yml b/.github/workflows/formal-verification.yml index b453b263..c1a32c0b 100644 --- a/.github/workflows/formal-verification.yml +++ b/.github/workflows/formal-verification.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # formal-verification.yml — Creusot formal verification of the trust-pipeline kernel. diff --git a/.github/workflows/generator-generic-ossf-slsa3-publish.yml b/.github/workflows/generator-generic-ossf-slsa3-publish.yml index d11d3d4f..ac570fdf 100644 --- a/.github/workflows/generator-generic-ossf-slsa3-publish.yml +++ b/.github/workflows/generator-generic-ossf-slsa3-publish.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # This workflow uses actions that are not certified by GitHub. # They are provided by a third-party and are governed by # separate terms of service, privacy policy, and support diff --git a/.github/workflows/ghcr-publish.yml b/.github/workflows/ghcr-publish.yml index 6f6b8256..5b3e6b85 100644 --- a/.github/workflows/ghcr-publish.yml +++ b/.github/workflows/ghcr-publish.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Publish to GHCR permissions: diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index da4c97f9..f73066ea 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Governance on: diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 7408eaba..c670d1c6 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Hypatia Security Scan on: diff --git a/.github/workflows/idris2-abi-ci.yml b/.github/workflows/idris2-abi-ci.yml index a24a0614..b3c001f1 100644 --- a/.github/workflows/idris2-abi-ci.yml +++ b/.github/workflows/idris2-abi-ci.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Idris2 ABI Type-Check on: diff --git a/.github/workflows/live-provers.yml b/.github/workflows/live-provers.yml index efcce914..6759c565 100644 --- a/.github/workflows/live-provers.yml +++ b/.github/workflows/live-provers.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # ECHIDNA — Live-Prover CI # # Exercises real prover binaries against canonical micro-goals. Complements diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 2d14e71d..430ef81b 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: diff --git a/.github/workflows/mvp-smoke.yml b/.github/workflows/mvp-smoke.yml index 8aa68d35..43e30c68 100644 --- a/.github/workflows/mvp-smoke.yml +++ b/.github/workflows/mvp-smoke.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: MVP Smoke (Best Effort) on: diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index 62c46b32..bb10ea65 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: GitHub Pages (Ddraig SSG) on: push: diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index e30eb284..e39b5b5e 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Rust CI — thin wrapper calling the shared estate reusable in # hyperpolymath/standards. Configure once, propagate everywhere. # See: docs/CI-REUSABLE-WORKFLOWS.adoc in standards. @@ -11,6 +12,7 @@ on: pull_request: permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/s4-loop.yml b/.github/workflows/s4-loop.yml index 6857a3f8..cbf413fd 100644 --- a/.github/workflows/s4-loop.yml +++ b/.github/workflows/s4-loop.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # S4 loop-closure CI — brings up verisim-api as a service container and # runs the echidna s4_loop_closure integration test. Filed once # ghcr.io/hyperpolymath/verisimdb-api:latest became available (PR #121). diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 7daf8a93..0f6fd476 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: OSSF Scorecard on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 9558cb92..c4959a84 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Secret Scanner on: @@ -12,6 +13,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: @@ -19,5 +21,5 @@ jobs: # caller must grant at least that or the run startup-fails. permissions: contents: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) secrets: inherit diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index de0cef9a..dea6bdd6 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. name: Security Scan diff --git a/.github/workflows/server-boot-gate.yml b/.github/workflows/server-boot-gate.yml index 9d900c78..8a0ab3bf 100644 --- a/.github/workflows/server-boot-gate.yml +++ b/.github/workflows/server-boot-gate.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Server boot gate — builds the echidna binary, boots the server, and # verifies that /api/health, /api/provers, and a session {id} route all # respond. Exists so "compiles" can never again mean "boots" — the diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index f581a0e8..2c843226 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Estate SPARK Theatre Gate — thin caller of the reusable workflow in # hyperpolymath/standards (#135 / #141). Pinned by commit SHA per the # estate action-pinning policy. Regenerate the pin only when the reusable diff --git a/.github/workflows/verification-proofs-cron.yml b/.github/workflows/verification-proofs-cron.yml index 8c9ed337..abfb7c93 100644 --- a/.github/workflows/verification-proofs-cron.yml +++ b/.github/workflows/verification-proofs-cron.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Weekly verification of the heavier self-proof corpora that are too slow and too # network-heavy to gate on every PR: currently Isabelle/HOL (proofs/isabelle). The # Isabelle toolchain is a large, non-apt download (~500MB tarball), so this runs on diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index bcaea649..c3cf64db 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,5 +1,6 @@ # SPDX-License-Identifier: AGPL-3.0-or-later # This workflow is managed by gh actions-lock. +# This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter