diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index c39d3e1..afd1eb2 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -5,7 +5,7 @@ version: 'v0.0.2' workflows: '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' + - 'github/codeql-action@v4.38.2' '.github/workflows/container-build.yml': - 'actions/checkout@v7.0.1' '.github/workflows/dependabot-automerge.yml': @@ -167,9 +167,9 @@ dependencies: commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938' owner_id: 9919 repo_id: 259445878 - 'github/codeql-action@v4.38.0': - ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + 'github/codeql-action@v4.38.2': + ref: 'v4.38.2' + commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' owner_id: 9919 repo_id: 259445878 'goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406': diff --git a/CHANGELOG.adoc b/CHANGELOG.adoc index 4c2ee67..93bc5b4 100644 --- a/CHANGELOG.adoc +++ b/CHANGELOG.adoc @@ -46,6 +46,10 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. `branches/{b}/protection` `required_status_checks` populates the gate identically (contexts unioned when both mechanisms exist), and a 403 there is a hard error, never a no-gate — issue #100. +* `actions.lock` re-synced after Dependabot (#111) bumped `github/codeql-action` + to v4.38.2 in `codeql.yml`; Dependabot cannot edit the lockfile, so the lock + still pinned v4.38.0. Symptoms on `main`: Lock Sync Gate and governance + Actions lockfile verify red, CodeQL `startup_failure` — issue #105. * `actions.lock` desync: `standards-pipeline.yml`'s job-level reusable ref (`hyperpolymath/standards@ed5e3f65…`) was unlisted. Its entry and dependency record (with transitive closure) are now present — Lock Sync @@ -53,10 +57,12 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. * All 27 workflow files whose `gh actions-lock` stamp had displaced the SPDX header off line 1 now carry `# SPDX-License-Identifier: MPL-2.0` as byte 1 again — `lint-workflows / Check SPDX Headers` red on `main`, issue #105. -* Unrendered `{{PLACEHOLDER}}` tokens across `.devcontainer/`, `.envrc`, - `.github/SUPPORT`, `.github/.mailmap`, `.github/MAINTAINERS`, - `.github/CODE_OF_CONDUCT.md`, `.github/copilot-instructions.md` and the - `.machine_readable/ai/` rule files. +* Unrendered template placeholder tokens (the double-brace form) across + `.devcontainer/`, `.envrc`, `.github/SUPPORT`, `.github/.mailmap`, + `.github/MAINTAINERS`, `.github/CODE_OF_CONDUCT.md`, + `.github/copilot-instructions.md` and the `.machine_readable/ai/` rule files. + (This entry must not spell the token out: the OpenSSF Compliance gate greps + the changelog for it, and quoting it here turned that gate red on `main`.) ==== Removed