chore(deps): bump the actions group with 2 updates - #1060
Merged
Merged
Conversation
Bumps the actions group with 2 updates: [haskell-actions/setup](https://github.com/haskell-actions/setup) and [tailscale/github-action](https://github.com/tailscale/github-action). Updates `haskell-actions/setup` from 2.12.0 to 2.12.1 - [Release notes](https://github.com/haskell-actions/setup/releases) - [Commits](haskell-actions/setup@6037f33...0f8e8c9) Updates `tailscale/github-action` from 4.1.3 to 4.2.0 - [Release notes](https://github.com/tailscale/github-action/releases) - [Commits](tailscale/github-action@780049a...d1b6cd2) --- updated-dependencies: - dependency-name: haskell-actions/setup dependency-version: 2.12.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: tailscale/github-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
approved these changes
Sep 28, 2026
hyperpolymath
deleted the
dependabot/github_actions/actions-a52b0d501e
branch
September 28, 2026 13:32
hyperpolymath
added a commit
that referenced
this pull request
Sep 29, 2026
… and verifications (#1064) ## Summary Executes Phases 0–2 of `ULTRAPLAN-2026-09-29.adoc`, repairing the active CI regressions on `main` and landing the repo-local fixes and regression suites for the triaged P0/P1/P2 issues: 1. **#1050 (P0) & #1054 (P1) — `.github/workflows/hypatia-scan-reusable.yml`, `.github/workflows/governance-reusable.yml`, `scripts/tests/hypatia-blocking-gate-test.sh`, `scripts/tests/science-ci-security-test.rb`**: - Reproduced `#1050` against runs `36504013478` and `36504013387`: upstream `hyperpolymath/hypatia` broke `mix escript.build` at `4654d7a3d4` (`hyperpolymath/hypatia#869`, unescaped `/` inside `~r/.../` character class at `lib/rules/pin_integrity.ex:56`; last compilable commit is `9f2f62f5c9463c79b33a5ebf54372166ce56f349`). When `Build Hypatia scanner` failed, `Relativize finding paths`, `Filter SARIF through the baseline before upload`, `Upload SARIF to code scanning`, and `Upload findings artifacts` still executed due to `if: always()`, causing `Upload SARIF to code scanning` to fail on a nonexistent `hypatia.sarif` (`Path does not exist: hypatia.sarif`). - Removed `if: always()` from those four post-validation steps (which already sit upstream of the blocking gates), added a targeted hold on `9f2f62f5c9463c79b33a5ebf54372166ce56f349` for the 4-commit `hypatia#869` broken window (`4654d7a3d4..4f9874e3f5`) in both `hypatia-scan-reusable.yml` and `governance-reusable.yml` (automatically resuming `HEAD` once upstream `hypatia` advances), and restored single-document `jq -e -s` validation in `Validate findings and count severities` so a clean `[]` scan is a positive control while empty/whitespace/truncated/multi-document output fails closed (`#1054`). 2. **#1040 (P1) — `scripts/apply-branch-gates.sh`, `config/rulesets/gates.json`, `scripts/tests/branch-gates-apply-test.sh`**: - Added `yaml_has_pr_trigger` / `wf_triggers_on_pr` so `apply-branch-gates.sh` verifies that each candidate gate workflow triggers on `pull_request` / `pull_request_target` targeting the default branch before deriving its job contexts into `required_status_checks`, reporting `no_pr_trigger=[<wf>]` (and `UNGATED` if zero contexts survive). Added Case 26 and Mutant J in `scripts/tests/branch-gates-apply-test.sh` (103/103 passing). 3. **#1036 (P1) — `scripts/reconcile-scorecard-actions-lock.rb`, `scripts/tests/reconcile-scorecard-actions-lock-test.rb`**: - Updated `ScorecardActionsLock` to handle both directions of `gh-actions-lock v0.1.6`'s blindness to job-level reusable workflow `uses:` refs: (AC1) accepting `stale` findings whose `dependency` (`owner/repo@ref`) is referenced by a job-level reusable `uses:` in that workflow, and (AC2 / Arm D) failing closed when a workflow's job-level reusable `uses:` ref is absent from `.github/workflows/actions.lock`. 4. **#1032 (P1, items 3 & 4) — `scripts/apply-tag-ruleset-canon.sh`, `config/README.adoc`, `tests/test_tag_ruleset_canon.sh`**: - Enforced `.source_type == "Repository"` before repo-level `PUT` in `scripts/apply-tag-ruleset-canon.sh` (failing closed with `REFUSED-NO-SOURCE-TYPE` when `.source_type` is absent and reporting `ORG-INHERITED` for `.source_type == "Organization"`), updated `config/README.adoc`, and added Property 14 + mutant test in `tests/test_tag_ruleset_canon.sh` (31/31 passing). 5. **#1037 (AC5) — `docs/DEPENDABOT-POLICY.adoc`**: - Documented the `dependency-name: "github/codeql-action*"` trailing-wildcard requirement for subpath actions and its revisit trigger, plus recorded the live 48-PR re-enumeration in `ULTRAPLAN-2026-09-29.adoc`. 6. **#1058 (Finding 2) — `1-formats/deed/spec/abnf/deed.abnf` & `.machine_readable/REGISTRY.a2ml`**: - Removed the orphaned `; pending owner ruling. Grammar below is unchanged.` line and regenerated `.machine_readable/REGISTRY.a2ml` (`scripts/tests/build-registry-test.sh` 9/9 passing). 7. **Additional `main` CI & script repairs**: - Updated `.github/workflows/actions.lock` for `#1060` (`haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d` and `tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd`) and guarded `scripts/update-actions-lock.sh` against empty verifier stdout (`scripts/tests/actions-lock-update-test.sh` 12/12 passing). - Repaired the duplicate `if [ ! -s "$cache" ]` merge artifact in `scripts/apply-protection-floor.sh` (`#1031`; `scripts/tests/protection-floor-test.sh` 50/50 passing). - Cleared retired `launcher-standard` filename tokens from `ULTRAPLAN-2026-09-24.adoc` and `ULTRAPLAN-2026-09-29.adoc` (`scripts/tests/check-launcher-standard-currency-test.sh` 19/19 passing). - Added `scripts/triage-2026-09-29-apply.sh` and `scripts/tests/triage-2026-09-29-apply-test.sh`. ## Issue Links (Verified Phase 0 & Phase 1/2 Resolutions) Closes #1057 Closes #956 Closes #1013 Closes #1005 Closes #637 Closes #709 Closes #715 Closes #784 Closes #1050 Closes #1054 Closes #1040 Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 2 updates: haskell-actions/setup and tailscale/github-action.
Updates
haskell-actions/setupfrom 2.12.0 to 2.12.1Release notes
Sourced from haskell-actions/setup's releases.
Commits
0f8e8c9Add Cabal 3.18.1.0 and Stack 3.11.1Updates
tailscale/github-actionfrom 4.1.3 to 4.2.0Release notes
Sourced from tailscale/github-action's releases.
Commits
d1b6cd2Merge pull request #314 from tailscale/dependabot/github_actions/actions/chec...f2a4d78Bump actions/checkout from 7.0.0 to 7.0.1a122c34Merge pull request #312 from tailscale/dependabot/github_actions/actions/setu...55d8693Bump actions/setup-node from 6.4.0 to 7.0.0546937cBump typescript from 5.9.3 to 6.0.30e42fa1fix: reuse stale tailscale.tgz on self-hosted runners508737eMerge pull request #304 from tailscale/log_groups5a0d794extract logging function into its own classba16990catch errors191eb01buildDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions