-
-
Notifications
You must be signed in to change notification settings - Fork 0
Execute CMake and pipeline commands with failure propagation #64
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
d3b7959
3a12ba7
6affed2
8d8065f
c24a52c
be2ccd8
083e1df
1587fa9
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,6 +1,5 @@ | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # This workflow is managed by gh actions-lock. | ||
| # This workflow is managed by gh actions-lock. | ||
| name: Governance | ||
|
|
||
| on: | ||
|
|
@@ -16,4 +15,4 @@ permissions: | |
|
|
||
| jobs: | ||
| governance: | ||
| uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a | ||
| uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@469605210e767ee94d1c7a9c13cb6a1d0a78cad1 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/sh
set -eu
expected='469605210e767ee94d1c7a9c13cb6a1d0a78cad1'
lock='.github/workflows/actions.lock'
test -f "$lock"
for workflow in governance.yml hypatia-scan.yml; do
ref="$(
rg -o 'hyperpolymath/standards/\.github/workflows/[^@]+@[0-9a-f]{40}' \
".github/workflows/$workflow" |
sed 's/.*`@//`'
)"
test "$ref" = "$expected"
grep -F "$ref" "$lock" >/dev/null
doneRepository: hyperpolymath/halideiser Length of output: 162 🏁 Script executed: #!/bin/sh
set -eu
printf '%s\n' '--- workflow references ---'
for workflow in governance.yml hypatia-scan.yml; do
printf '%s\n' "$workflow"
sed -n '1,35p' ".github/workflows/$workflow"
done
printf '%s\n' '--- lockfile matches ---'
test -f .github/workflows/actions.lock
rg -n -C 2 'hyperpolymath/standards|469605210e767ee94d1c7a9c13cb6a1d0a78cad1' .github/workflows/actions.lock || true
printf '%s\n' '--- lockfile metadata ---'
wc -l .github/workflows/actions.lock
sed -n '1,80p' .github/workflows/actions.lockRepository: hyperpolymath/halideiser Length of output: 4269 🤖 get_repo_knowledge executed:
Length of output: 4080 🏁 Script executed: #!/bin/sh
set -eu
for workflow in governance.yml hypatia-scan.yml; do
printf '%s\n' "[$workflow]"
ref="$(rg -o 'hyperpolymath/standards/\.github/workflows/[^@]+@[0-9a-f]{40}' ".github/workflows/$workflow" | sed 's/.*`@//`')"
printf 'resolved_ref=%s\n' "$ref"
printf 'exact_lock_matches:\n'
grep -n -F "$ref" .github/workflows/actions.lock || true
done
printf '%s\n' '[lockfile references for standards]'
rg -n 'hyperpolymath/standards|governance-reusable|hypatia' .github/workflows/actions.lock || trueRepository: hyperpolymath/halideiser Length of output: 430 🌐 Web query:
💡 Result: GitHub does not have a single, universal "native" lockfile format for all Actions that is automatically enforced by the platform [1][2]. Instead, the ecosystem uses community-driven tooling and emerging standards to address the need for dependency pinning and integrity verification [3][4][1]. The "actions.lock" file refers to an emerging, authoritative lockfile format developed as part of GitHub's ongoing efforts to improve supply chain security for Actions [3][4]. Key details include: The Lockfile Format: The standard lockfile, often located at.github/workflows/actions.lock, is a YAML file designed to record the resolved transitive dependency graph for a repository's workflows [3][5]. It typically maps "pin keys" (e.g., OWNER/REPO@REF) to resolved metadata, including commit SHAs [3][6]. This allows tools to audit and verify that the exact action versions (including those pulled in by composite actions or reusable workflows) remain consistent across runs [3][4]. Tooling: Several tools utilize this or similar lockfile concepts to provide pinning functionality: - gh-actions-lock: A GitHub CLI extension that scans workflows, pins actions to verified commits, and maintains the.github/workflows/actions.lock file [4]. It enforces that all dependencies are present in the lockfile and verifies that the locked commit exists to prevent "impostor commit" attacks [4]. - actions-lockfile: A Go library provided by GitHub that defines the authoritative schema for this lockfile, intended for use by other security and auditing tools [3][6]. - Other approaches: Other third-party tools like actionspack or various CLI extensions have implemented their own lockfile mechanisms (e.g., storing dependencies directly in the workflow YAML or using different file paths) to achieve similar goals [7][1][8]. Status: GitHub is actively working on formalizing "Locked Dependencies for GitHub Actions Workflows" (as seen in public roadmap items) to make dependencies more explicit and verifiable directly within the platform [2]. Because this is an evolving area, different repositories may use different tools or manual pinning strategies until a fully integrated, platform-native solution becomes standard [4][1][2]. In practice, if you encounter an actions.lock file, it is likely being managed by the gh-actions-lock extension or a similar tool to ensure that your CI/CD pipelines use immutable, verified code versions rather than mutable tags like Citations:
🌐 Web query:
💡 Result: The term actions.lock refers to a lockfile mechanism introduced by GitHub to improve the security and reproducibility of GitHub Actions workflows [1]. Specifically, it is associated with the project gh-actions-lock, which helps manage dependencies by pinning actions and reusable workflows to specific commit SHAs [1]. Key aspects of the actions.lock mechanism include: Security and Verification: The lockfile (located at.github/workflows/actions.lock) records the exact commit SHA for dependencies [1]. When a workflow is onboarded to use this lockfile, the system enforces that the actions executed on the runner match those specified in the lockfile, protecting against unauthorized changes or "impostor" commits [1]. It includes verification to ensure the commit exists and that the repository identity is validated [1]. Reusable Workflows and Actions: - Cross-Repository Dependencies: Actions or reusable workflows referenced from external repositories are pinned to specific SHAs within the lockfile [1]. - Same-Repository References: References to actions or reusable workflows located within the same repository (using the./ syntax) are inherently pinned because they resolve to the running commit SHA of the repository itself [1]. The tooling automatically converts these to the $ syntax to signify they are internally resolved, meaning they do not require an entry in the lockfile [1]. The gh-actions-lock tool is designed to scan workflows in a repository, pin resolvable dependencies, and generate or update the.github/workflows/actions.lock file [1]. Workflows are onboarded to this mechanism on a per-workflow basis [1]. Citations: Regenerate and verify the Actions lockfile.
🤖 Prompt for AI AgentsSource: MCP tools
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. yes do it rabbit
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Rate Limit Exceeded
|
||
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -1,6 +1,5 @@ | ||||||
| # SPDX-License-Identifier: MPL-2.0 | ||||||
| # This workflow is managed by gh actions-lock. | ||||||
| # This workflow is managed by gh actions-lock. | ||||||
| name: OSSF Scorecard | ||||||
|
|
||||||
| on: | ||||||
|
|
@@ -14,4 +13,9 @@ permissions: | |||||
|
|
||||||
| jobs: | ||||||
| scorecard: | ||||||
| permissions: | ||||||
| actions: read | ||||||
| contents: read | ||||||
| security-events: write | ||||||
|
coderabbitai[bot] marked this conversation as resolved.
|
||||||
| id-token: write | ||||||
| uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a | ||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🤖 get_repo_knowledge executed:
Length of output: 4093 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow files ---'
cat -n .github/workflows/scorecard.yml
printf '%s\n' '--- related workflow references ---'
rg -n -C 2 'hyperpolymath/standards/.github/workflows/(scorecard-reusable|governance|hypatia)|469605210e767ee94d1c7a9c13cb6a1d0a78cad1|84355587cb2a1f86e6882de83514a32db2646e7a' .github
printf '%s\n' '--- lockfile candidates ---'
git ls-files | rg '(^|/)(.*lock.*|.*actions.*)$|\.github' | head -200Repository: hyperpolymath/halideiser Length of output: 3743 🌐 Web query:
💡 Result: The file scorecard-reusable.yml is a centralized, reusable GitHub Actions workflow maintained within the hyperpolymath/standards repository [1][2]. This repository serves as the canonical source for policies, templates, and specifications across the Hyperpolymath ecosystem [2][3]. The scorecard-reusable.yml workflow is designed to automate supply-chain security analysis using the OpenSSF Scorecard action [1][4][5]. Because it is a reusable workflow, it is called by individual project repositories to maintain consistent security standards [1][6][5]. When implementing this workflow, projects must ensure that the calling job grants the necessary permissions. Specifically, documentation and related pull requests note that the caller must grant security-events: write and id-token: write within the job-level permissions block of the calling workflow [7][8][9]. This is necessary because permissions for reusable workflows are capped by the caller's defined permissions, and a failure to explicitly set these can lead to a silent startup_failure, preventing the Scorecard action from uploading its SARIF results [7][9]. The hyperpolymath/standards repository acts as the central hub for these governance and CI/CD tools, replacing a previous hub-satellite architecture to allow for easier maintenance and atomic cross-specification updates [2]. Other repositories (such as the rsr-template-repo) use this reusable workflow as part of their standard CI/CD scaffolding [4][3]. Citations:
🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- actions lock entries ---'
rg -n -C 3 'hyperpolymath/standards|scorecard-reusable|codeql-action/upload-sarif' .github/workflows/actions.lock || true
printf '%s\n' '--- referenced commit objects ---'
for sha in 84355587cb2a1f86e6882de83514a32db2646e7a 469605210e767ee94d1c7a9c13cb6a1d0a78cad1; do
printf '%s: ' "$sha"
curl -fsSL "https://api.github.com/repos/hyperpolymath/standards/commits/$sha" | python3 -c 'import json,sys; d=json.load(sys.stdin); print(d.get("sha", "NO_COMMIT"), d.get("message","").splitlines()[0])'
done
printf '%s\n' '--- reusable workflow at both pins ---'
for sha in 84355587cb2a1f86e6882de83514a32db2646e7a 469605210e767ee94d1c7a9c13cb6a1d0a78cad1; do
printf '\n### %s\n' "$sha"
curl -fsSL "https://raw.githubusercontent.com/hyperpolymath/standards/$sha/.github/workflows/scorecard-reusable.yml" | rg -n 'uses:|permissions:|security-events|id-token|upload-sarif|scorecard'
doneRepository: hyperpolymath/halideiser Length of output: 377 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- lockfile format and standards references ---'
sed -n '1,220p' .github/workflows/actions.lockRepository: hyperpolymath/halideiser Length of output: 4629 🏁 Script executed: #!/bin/bash
set +e
for sha in 84355587cb2a1f86e6882de83514a32db2646e7a 469605210e767ee94d1c7a9c13cb6a1d0a78cad1; do
printf '\n--- commit %s ---\n' "$sha"
curl -sS -L -w '\nHTTP_STATUS:%{http_code}\n' \
-H 'Accept: application/vnd.github+json' \
"https://api.github.com/repos/hyperpolymath/standards/commits/$sha"
printf '\n--- workflow %s ---\n' "$sha"
curl -sS -L -w '\nHTTP_STATUS:%{http_code}\n' \
"https://raw.githubusercontent.com/hyperpolymath/standards/$sha/.github/workflows/scorecard-reusable.yml"
doneRepository: hyperpolymath/halideiser Length of output: 50381 🏁 Script executed: #!/bin/bash
set -eu
log=/tmp/coderabbit-shell-logs/shell-output-uRhBLA
printf '%s\n' '--- response headers/status markers ---'
rg -n -- '--- commit|--- workflow|HTTP_STATUS|^ "sha": "843555|^ "sha": "469605|scorecard-reusable|upload-sarif|error|message' "$log" | head -120Repository: hyperpolymath/halideiser Length of output: 50383 🏁 Script executed: #!/bin/bash
set -eu
for sha in 84355587cb2a1f86e6882de83514a32db2646e7a 469605210e767ee94d1c7a9c13cb6a1d0a78cad1; do
printf '\n--- commit %s ---\n' "$sha"
curl -fsSL "https://api.github.com/repos/hyperpolymath/standards/commits/$sha" |
python3 -c '
import json,sys
d=json.load(sys.stdin)
print("sha:", d.get("sha"))
print("message:", d.get("commit",{}).get("message","").splitlines()[0])
for f in d.get("files",[]):
if f.get("filename") == ".github/workflows/scorecard-reusable.yml":
print("workflow_status:", f.get("status"), "changes:", f.get("changes"))
'
printf '%s\n' '--- workflow ---'
curl -fsSL "https://raw.githubusercontent.com/hyperpolymath/standards/$sha/.github/workflows/scorecard-reusable.yml" |
rg -n 'uses:|permissions:|security-events|id-token|upload-sarif|scorecard'
doneRepository: hyperpolymath/halideiser Length of output: 1812 🏁 Script executed: #!/bin/bash
set -eu
curl -fsSL 'https://api.github.com/repos/hyperpolymath/standards/compare/84355587cb2a1f86e6882de83514a32db2646e7a...469605210e767ee94d1c7a9c13cb6a1d0a78cad1' |
python3 -c '
import json,sys
d=json.load(sys.stdin)
print("status:", d.get("status"))
print("ahead_by:", d.get("ahead_by"), "behind_by:", d.get("behind_by"))
for f in d.get("files", []):
if f.get("filename") == ".github/workflows/scorecard-reusable.yml":
print(f.get("patch","<no patch>"))
'Repository: hyperpolymath/halideiser Length of output: 657 Update the Scorecard reusable-workflow pin. The older pin uses a Proposed fix- uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
+ uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@469605210e767ee94d1c7a9c13cb6a1d0a78cad1The Actions lockfile currently lists 📝 Committable suggestion
Suggested change
🤖 Prompt for AI AgentsSource: MCP tools
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fix logic is sound, do it
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Rate Limit Exceeded
|
||||||
Uh oh!
There was an error while loading. Please reload this page.