Skip to content

chore(deps): bump the actions group with 2 updates - #1060

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-a52b0d501e
Sep 28, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-a52b0d501e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates: haskell-actions/setup and tailscale/github-action.

Updates haskell-actions/setup from 2.12.0 to 2.12.1

Release notes

Sourced from haskell-actions/setup's releases.

v2.12.1

Add Cabal 3.18.1.0 and Stack 3.11.1

What's Changed

Full Changelog: haskell-actions/setup@v2.12.0...v2.12.1

Commits

Updates tailscale/github-action from 4.1.3 to 4.2.0

Release notes

Sourced from tailscale/github-action's releases.

v4.2.0

What's Changed

New Contributors

Full Changelog: tailscale/github-action@v4.1.3...v4.2.0

Commits
  • d1b6cd2 Merge pull request #314 from tailscale/dependabot/github_actions/actions/chec...
  • f2a4d78 Bump actions/checkout from 7.0.0 to 7.0.1
  • a122c34 Merge pull request #312 from tailscale/dependabot/github_actions/actions/setu...
  • 55d8693 Bump actions/setup-node from 6.4.0 to 7.0.0
  • 546937c Bump typescript from 5.9.3 to 6.0.3
  • 0e42fa1 fix: reuse stale tailscale.tgz on self-hosted runners
  • 508737e Merge pull request #304 from tailscale/log_groups
  • 5a0d794 extract logging function into its own class
  • ba16990 catch errors
  • 191eb01 build
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 2 updates: [haskell-actions/setup](https://github.com/haskell-actions/setup) and [tailscale/github-action](https://github.com/tailscale/github-action).


Updates `haskell-actions/setup` from 2.12.0 to 2.12.1
- [Release notes](https://github.com/haskell-actions/setup/releases)
- [Commits](haskell-actions/setup@6037f33...0f8e8c9)

Updates `tailscale/github-action` from 4.1.3 to 4.2.0
- [Release notes](https://github.com/tailscale/github-action/releases)
- [Commits](tailscale/github-action@780049a...d1b6cd2)

---
updated-dependencies:
- dependency-name: haskell-actions/setup
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: tailscale/github-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner September 28, 2026 13:30
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7a6932ad-29ed-497f-8e63-0914acf82216

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 6e98f4b into main Sep 28, 2026
38 of 46 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-a52b0d501e branch September 28, 2026 13:32
hyperpolymath added a commit that referenced this pull request Sep 29, 2026
… and verifications (#1064)

## Summary

Executes Phases 0–2 of `ULTRAPLAN-2026-09-29.adoc`, repairing the active
CI regressions on `main` and landing the repo-local fixes and regression
suites for the triaged P0/P1/P2 issues:

1. **#1050 (P0) & #1054 (P1) —
`.github/workflows/hypatia-scan-reusable.yml`,
`.github/workflows/governance-reusable.yml`,
`scripts/tests/hypatia-blocking-gate-test.sh`,
`scripts/tests/science-ci-security-test.rb`**:
- Reproduced `#1050` against runs `36504013478` and `36504013387`:
upstream `hyperpolymath/hypatia` broke `mix escript.build` at
`4654d7a3d4` (`hyperpolymath/hypatia#869`, unescaped `/` inside
`~r/.../` character class at `lib/rules/pin_integrity.ex:56`; last
compilable commit is `9f2f62f5c9463c79b33a5ebf54372166ce56f349`). When
`Build Hypatia scanner` failed, `Relativize finding paths`, `Filter
SARIF through the baseline before upload`, `Upload SARIF to code
scanning`, and `Upload findings artifacts` still executed due to `if:
always()`, causing `Upload SARIF to code scanning` to fail on a
nonexistent `hypatia.sarif` (`Path does not exist: hypatia.sarif`).
- Removed `if: always()` from those four post-validation steps (which
already sit upstream of the blocking gates), added a targeted hold on
`9f2f62f5c9463c79b33a5ebf54372166ce56f349` for the 4-commit
`hypatia#869` broken window (`4654d7a3d4..4f9874e3f5`) in both
`hypatia-scan-reusable.yml` and `governance-reusable.yml` (automatically
resuming `HEAD` once upstream `hypatia` advances), and restored
single-document `jq -e -s` validation in `Validate findings and count
severities` so a clean `[]` scan is a positive control while
empty/whitespace/truncated/multi-document output fails closed (`#1054`).
2. **#1040 (P1) — `scripts/apply-branch-gates.sh`,
`config/rulesets/gates.json`,
`scripts/tests/branch-gates-apply-test.sh`**:
- Added `yaml_has_pr_trigger` / `wf_triggers_on_pr` so
`apply-branch-gates.sh` verifies that each candidate gate workflow
triggers on `pull_request` / `pull_request_target` targeting the default
branch before deriving its job contexts into `required_status_checks`,
reporting `no_pr_trigger=[<wf>]` (and `UNGATED` if zero contexts
survive). Added Case 26 and Mutant J in
`scripts/tests/branch-gates-apply-test.sh` (103/103 passing).
3. **#1036 (P1) — `scripts/reconcile-scorecard-actions-lock.rb`,
`scripts/tests/reconcile-scorecard-actions-lock-test.rb`**:
- Updated `ScorecardActionsLock` to handle both directions of
`gh-actions-lock v0.1.6`'s blindness to job-level reusable workflow
`uses:` refs: (AC1) accepting `stale` findings whose `dependency`
(`owner/repo@ref`) is referenced by a job-level reusable `uses:` in that
workflow, and (AC2 / Arm D) failing closed when a workflow's job-level
reusable `uses:` ref is absent from `.github/workflows/actions.lock`.
4. **#1032 (P1, items 3 & 4) — `scripts/apply-tag-ruleset-canon.sh`,
`config/README.adoc`, `tests/test_tag_ruleset_canon.sh`**:
- Enforced `.source_type == "Repository"` before repo-level `PUT` in
`scripts/apply-tag-ruleset-canon.sh` (failing closed with
`REFUSED-NO-SOURCE-TYPE` when `.source_type` is absent and reporting
`ORG-INHERITED` for `.source_type == "Organization"`), updated
`config/README.adoc`, and added Property 14 + mutant test in
`tests/test_tag_ruleset_canon.sh` (31/31 passing).
5. **#1037 (AC5) — `docs/DEPENDABOT-POLICY.adoc`**:
- Documented the `dependency-name: "github/codeql-action*"`
trailing-wildcard requirement for subpath actions and its revisit
trigger, plus recorded the live 48-PR re-enumeration in
`ULTRAPLAN-2026-09-29.adoc`.
6. **#1058 (Finding 2) — `1-formats/deed/spec/abnf/deed.abnf` &
`.machine_readable/REGISTRY.a2ml`**:
- Removed the orphaned `; pending owner ruling. Grammar below is
unchanged.` line and regenerated `.machine_readable/REGISTRY.a2ml`
(`scripts/tests/build-registry-test.sh` 9/9 passing).
7. **Additional `main` CI & script repairs**:
- Updated `.github/workflows/actions.lock` for `#1060`
(`haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d` and
`tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd`) and
guarded `scripts/update-actions-lock.sh` against empty verifier stdout
(`scripts/tests/actions-lock-update-test.sh` 12/12 passing).
- Repaired the duplicate `if [ ! -s "$cache" ]` merge artifact in
`scripts/apply-protection-floor.sh` (`#1031`;
`scripts/tests/protection-floor-test.sh` 50/50 passing).
- Cleared retired `launcher-standard` filename tokens from
`ULTRAPLAN-2026-09-24.adoc` and `ULTRAPLAN-2026-09-29.adoc`
(`scripts/tests/check-launcher-standard-currency-test.sh` 19/19
passing).
- Added `scripts/triage-2026-09-29-apply.sh` and
`scripts/tests/triage-2026-09-29-apply-test.sh`.

## Issue Links (Verified Phase 0 & Phase 1/2 Resolutions)

Closes #1057
Closes #956
Closes #1013
Closes #1005
Closes #637
Closes #709
Closes #715
Closes #784
Closes #1050
Closes #1054
Closes #1040

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant