-
-
Notifications
You must be signed in to change notification settings - Fork 0
spec: distinguish resolution design and executable fragment #74
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
1cd6299
5037852
8e865fc
5ec5c40
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,130 @@ | ||
| # This file is machine-generated by `gh actions-lock`. | ||
| # Do not edit by hand; run `gh actions-lock` to update. | ||
| # Docs: https://gh.io/actions-lockfile | ||
| version: 'v0.0.2' | ||
| workflows: | ||
| '.github/workflows/boj-build.yml': | ||
| - 'actions/checkout@v6.0.2' | ||
| '.github/workflows/codeql.yml': | ||
| - 'actions/checkout@v6.0.2' | ||
| - 'github/codeql-action@v4.34.0' | ||
| '.github/workflows/dependabot-automerge.yml': | ||
| - 'dependabot/fetch-metadata@v2.2.0' | ||
| '.github/workflows/dogfood-gate.yml': | ||
| - 'actions/checkout@v4.3.1' | ||
| - 'hyperpolymath/deed-ecosystem@main' | ||
| '.github/workflows/e2e.yml': | ||
| - 'actions/checkout@v6.0.2' | ||
| - 'goto-bus-stop/setup-zig@v2.2.1' | ||
| '.github/workflows/fragment-conformance.yml': | ||
| - 'actions/checkout@v7.0.0' | ||
| - 'julia-actions/setup-julia@v2.7.0' | ||
| '.github/workflows/instant-sync.yml': | ||
| - 'peter-evans/repository-dispatch@v4.0.1' | ||
| '.github/workflows/openssf-compliance.yml': | ||
| - 'actions/checkout@v4.3.1' | ||
| '.github/workflows/pages.yml': | ||
| - 'actions/checkout@v6.0.2' | ||
| - 'actions/deploy-pages@v4.0.5' | ||
| - 'actions/upload-pages-artifact@v3.0.1' | ||
| '.github/workflows/push-email-notify.yml': | ||
| - 'hyperpolymath/smtp-notify-action@v0.2.0' | ||
| '.github/workflows/release.yml': | ||
| - 'actions/checkout@v6.0.2' | ||
| - 'actions/upload-artifact@v4.6.2' | ||
| - 'softprops/action-gh-release@v2.5.0' | ||
| '.github/workflows/rhodibot.yml': | ||
| - 'actions/checkout@v4.3.1' | ||
| '.github/workflows/static-analysis-gate.yml': | ||
| - 'actions/checkout@v6.0.2' | ||
| - 'actions/download-artifact@v4.1.8' | ||
| - 'actions/upload-artifact@v4.6.2' | ||
| - 'erlef/setup-beam@v1.20.4' | ||
| dependencies: | ||
| 'actions/checkout@v4.3.1': | ||
| ref: 'v4.3.1' | ||
| commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' | ||
| owner_id: 44036562 | ||
| repo_id: 197814629 | ||
| 'actions/checkout@v6.0.2': | ||
| ref: 'v6.0.2' | ||
| commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' | ||
| owner_id: 44036562 | ||
| repo_id: 197814629 | ||
| 'actions/checkout@v7.0.0': | ||
| ref: 'v7.0.0' | ||
| commit: 'sha1-9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0' | ||
| owner_id: 44036562 | ||
| repo_id: 197814629 | ||
| 'actions/deploy-pages@v4.0.5': | ||
| ref: 'v4.0.5' | ||
| commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' | ||
| owner_id: 44036562 | ||
| repo_id: 438112499 | ||
| 'actions/download-artifact@v4.1.8': | ||
| ref: 'v4.1.8' | ||
| commit: 'sha1-fa0a91b85d4f404e444e00e005971372dc801d16' | ||
| owner_id: 44036562 | ||
| repo_id: 192626254 | ||
| 'actions/upload-artifact@v4': | ||
| ref: 'v4' | ||
| commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' | ||
| owner_id: 44036562 | ||
| repo_id: 192625955 | ||
| 'actions/upload-artifact@v4.6.2': | ||
| ref: 'v4.6.2' | ||
| commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' | ||
| owner_id: 44036562 | ||
| repo_id: 192625955 | ||
| 'actions/upload-pages-artifact@v3.0.1': | ||
| ref: 'v3.0.1' | ||
| commit: 'sha1-56afc609e74202658d3ffba0e8f6dda462b719fa' | ||
| owner_id: 44036562 | ||
| repo_id: 496012378 | ||
| uses: | ||
| - 'actions/upload-artifact@v4' | ||
| 'dependabot/fetch-metadata@v2.2.0': | ||
| ref: 'v2.2.0' | ||
| commit: 'sha1-dbb049abf0d677abbd7f7eee0375145b417fdd34' | ||
| owner_id: 27347476 | ||
| repo_id: 371068214 | ||
| 'erlef/setup-beam@v1.20.4': | ||
| ref: 'v1.20.4' | ||
| commit: 'sha1-e6d7c94229049569db56a7ad5a540c051a010af9' | ||
| owner_id: 47606891 | ||
| repo_id: 331103973 | ||
| 'github/codeql-action@v4.34.0': | ||
| ref: 'v4.34.0' | ||
| commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' | ||
| owner_id: 9919 | ||
| repo_id: 259445878 | ||
| 'goto-bus-stop/setup-zig@v2.2.1': | ||
| ref: 'v2.2.1' | ||
| commit: 'sha1-abea47f85e598557f500fa1fd2ab7464fcb39406' | ||
| owner_id: 1006268 | ||
| repo_id: 212984112 | ||
| 'hyperpolymath/deed-ecosystem@main': | ||
| ref: 'main' | ||
| commit: 'sha1-f7a40a4d5cc82b2e73f861119baa6818d77a448d' | ||
| owner_id: 6759885 | ||
| repo_id: 1275649586 | ||
| 'hyperpolymath/smtp-notify-action@v0.2.0': | ||
| ref: 'v0.2.0' | ||
| commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' | ||
| owner_id: 6759885 | ||
| repo_id: 1352485172 | ||
| 'julia-actions/setup-julia@v2.7.0': | ||
| ref: 'v2.7.0' | ||
| commit: 'sha1-4c0cb0fce8556fdb04a90347310e5db8b1f98fb9' | ||
| owner_id: 53965732 | ||
| repo_id: 202020219 | ||
| 'peter-evans/repository-dispatch@v4.0.1': | ||
| ref: 'v4.0.1' | ||
| commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' | ||
| owner_id: 18365890 | ||
| repo_id: 220359305 | ||
| 'softprops/action-gh-release@v2.5.0': | ||
| ref: 'v2.5.0' | ||
| commit: 'sha1-a06a81a03ee405af7f2048a818ed3f03bbf83c7b' | ||
| owner_id: 2242 | ||
| repo_id: 204253808 |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,4 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk> | ||
| # | ||
|
|
@@ -26,7 +27,7 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@v4.3.1 | ||
|
|
||
| - name: Check for A2ML files | ||
| id: detect | ||
|
|
@@ -43,7 +44,7 @@ | |
| # which taught the validator the colon/brace-block identity form | ||
| # (`id: "..."`), so docs/governance/TSDM.a2ml failed against the old | ||
| # pin despite being valid. Bumped to current main. | ||
| uses: hyperpolymath/a2ml-ecosystem/validate-action@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79 # main | ||
| uses: hyperpolymath/deed-ecosystem/validate-action@main | ||
|
Check failure on line 47 in .github/workflows/dogfood-gate.yml
|
||
| with: | ||
| path: '.' | ||
| strict: 'false' | ||
|
|
@@ -75,7 +76,7 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@v4.3.1 | ||
|
|
||
| - name: Check for K9 files | ||
| id: detect | ||
|
|
@@ -90,12 +91,40 @@ | |
| echo "::warning::Found $CONFIG_COUNT config files but no K9 contracts. Run k9iser to generate contracts." | ||
| fi | ||
|
|
||
| - name: Validate K9 contracts | ||
| - name: Check out the canonical K9 validator | ||
| if: steps.detect.outputs.k9_count > 0 | ||
| uses: hyperpolymath/k9-ecosystem/validate-action@89f3c2702f4f650a92aa7411502f38da06abd562 # main | ||
| uses: actions/checkout@v4.3.1 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -euo pipefail
rg -n 'uses:\s+[^[:space:]]+@(main|v[0-9][^[:space:]]*)' .github/workflowsRepository: hyperpolymath/krl Length of output: 3949 🤖 get_repo_knowledge executed:
Length of output: 3894 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- workflow excerpts ---'
sed -n '84,103p' .github/workflows/dogfood-gate.yml
sed -n '16,29p' .github/workflows/release.yml
printf '%s\n' '--- action-lock references ---'
rg -n -i 'lock|pin|immutable|renovate|pinact|zizmor|action' .github .github/workflows \
-g '*.yml' -g '*.yaml' -g '*.json' -g '*.md' || true
printf '%s\n' '--- tracked files related to action locks ---'
git ls-files | rg -i '(^|/)(action|workflow|github).*(lock|pin)|(^|/)(pinact|renovate|dependabot)' || true
printf '%s\n' '--- tag object types and dereferenced commits ---'
for spec in 'actions/checkout v4.3.1' 'actions/checkout v6.0.2'; do
set -- $spec
repo=$1
tag=$2
ref=$(gh api "repos/$repo/git/ref/tags/$tag")
type=$(printf '%s' "$ref" | jq -r '.object.type')
object=$(printf '%s' "$ref" | jq -r '.object.sha')
if [ "$type" = tag ]; then
commit=$(gh api "repos/$repo/git/tags/$object" | jq -r '.object.sha')
else
commit=$object
fi
resolved=$(gh api "repos/$repo/commits/$commit" | jq -r '.sha')
printf '%s: type=%s ref=%s commit=%s validated=%s\n' "$repo@$tag" "$type" "$object" "$commit" "$resolved"
doneRepository: hyperpolymath/krl Length of output: 28713 🏁 Script executed: #!/bin/bash
set -euo pipefail
for spec in 'actions/checkout v4.3.1' 'actions/checkout v6.0.2'; do
set -- $spec
repo=$1
tag=$2
ref=$(gh api "repos/$repo/git/ref/tags/$tag")
type=$(printf '%s' "$ref" | jq -r '.object.type')
object=$(printf '%s' "$ref" | jq -r '.object.sha')
if [ "$type" = tag ]; then
commit=$(gh api "repos/$repo/git/tags/$object" | jq -r '.object.sha')
else
commit=$object
fi
printf '%s type=%s ref=%s commit=%s\n' "$repo@$tag" "$type" "$object" "$commit"
gh api "repos/$repo/commits/$commit" --jq '.sha'
doneRepository: hyperpolymath/krl Length of output: 495 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- actions.lock entries for the affected workflows ---'
rg -n -C 8 'dogfood-gate|release\.yml|actions/checkout|34e114876b0b11c390a56381ad16ebd13914f8d5|de0fac2e4500dabe0009e67214ff5f5447ce83dd' .github/workflows/actions.lock
printf '%s\n' '--- lock-enforcement contract ---'
sed -n '1,28p' .github/workflows/labels.yml
sed -n '1,45p' .github/workflows/dependabot-automerge.ymlRepository: hyperpolymath/krl Length of output: 5872 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- all repository references to lock enforcement ---'
rg -n -i 'actions-lock|actions\.lock|commit:|startup_failure|immutable|sha[- ]?pin' . \
-g '!*.lock' -g '!LICENSE*' -g '!*.svg' | head -250
printf '%s\n' '--- workflow headers and security gates ---'
for f in .github/workflows/*.yml; do
if rg -q -i 'actions-lock|actions\.lock|zizmor|pinact|lock' "$f"; then
printf '\n### %s\n' "$f"
sed -n '1,80p' "$f"
fi
doneRepository: hyperpolymath/krl Length of output: 43240 🌐 Web query:
💡 Result: The file Citations:
Pin the checkout actions to immutable commits.
📍 Affects 2 files
🤖 Prompt for AI Agents |
||
| with: | ||
| path: '.' | ||
| strict: 'false' | ||
| repository: hyperpolymath/k9-ecosystem | ||
| ref: 347ee5d6a1b77831de56fe8da21a473724e4cac2 | ||
| path: .ci-k9-validator | ||
| persist-credentials: false | ||
| sparse-checkout-cone-mode: false | ||
| sparse-checkout: | | ||
| /validate-action/action.yml | ||
| /validate-action/validate-k9.sh | ||
|
|
||
| - name: Validate K9 contracts | ||
| if: steps.detect.outputs.k9_count > 0 | ||
| # Sparse checkout avoids unrelated dangling symlinks in the upstream | ||
| # action archive; execute the unchanged canonical validator. | ||
| env: | ||
| INPUT_PATH: '.' | ||
| INPUT_STRICT: 'false' | ||
| # Canonical action.yml defaults at the pinned validator revision. | ||
| INPUT_PATHS_IGNORE: | | ||
| vendor/ | ||
| vendored/ | ||
| verified-container-spec/ | ||
| .audittraining/ | ||
| integration/fixtures/ | ||
| test/fixtures/ | ||
| tests/fixtures/ | ||
| absolute-zero/ | ||
| coordination.k9 | ||
| session/custom-checks.k9 | ||
| self-validating/methodology-guard.k9.ncl | ||
| run: bash .ci-k9-validator/validate-action/validate-k9.sh | ||
|
|
||
| - name: Write summary | ||
| run: | | ||
|
|
@@ -125,7 +154,7 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@v4.3.1 | ||
|
|
||
| - name: Scan for invisible characters | ||
| id: lint | ||
|
|
@@ -190,7 +219,7 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@v4.3.1 | ||
|
|
||
| - name: Check for Groove manifest | ||
| id: groove | ||
|
|
@@ -249,7 +278,7 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@v4.3.1 | ||
|
|
||
| - name: Check and validate eclexiaiser manifest | ||
| id: eclex | ||
|
|
@@ -324,7 +353,7 @@ | |
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@v4.3.1 | ||
|
|
||
| - name: Generate dogfooding scorecard | ||
| run: | | ||
|
|
@@ -397,4 +426,3 @@ | |
| *Generated by the [Dogfood Gate](https://github.com/hyperpolymath/rsr-template-repo) workflow.* | ||
| *Dogfooding is guinea pig fooding — we test our tools on ourselves.* | ||
| EOF | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,38 @@ | ||
| # This workflow is managed by gh actions-lock. | ||
| # SPDX-License-Identifier: MPL-2.0 | ||
| name: KRL fragment conformance | ||
| on: | ||
| pull_request: | ||
| push: | ||
| branches: [main, master] | ||
| workflow_dispatch: | ||
| permissions: | ||
| contents: read | ||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
| jobs: | ||
| fragment: | ||
| name: KRL fragment conformance | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 15 | ||
| steps: | ||
| - name: Checkout specification | ||
| uses: actions/checkout@v7.0.0 | ||
| with: | ||
| persist-credentials: false | ||
| - name: Checkout pinned QuandleDB implementation | ||
| uses: actions/checkout@v7.0.0 | ||
| with: | ||
| repository: hyperpolymath/quandledb | ||
| ref: f1d0010e4e614fcb2c8428e555b9cdbb279d4da7 | ||
| path: deps/quandledb | ||
| persist-credentials: false | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
| - name: Record implementation revision | ||
| run: git -C deps/quandledb rev-parse HEAD | ||
| - name: Install Julia | ||
| uses: julia-actions/setup-julia@v2.7.0 | ||
|
Check failure on line 34 in .github/workflows/fragment-conformance.yml
|
||
| with: | ||
| version: '1.12.6' | ||
| - name: Check fragment syntax, execution and explicit refusal | ||
| run: julia --startup-file=no tests/conformance/retrieval_fragment.jl deps/quandledb | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Analyzed with Security Review | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: hyperpolymath/krl
Length of output: 1286
Security Misconfiguration
Reachability: External
Exploitability: Difficult
CWE: CWE-829 — Inclusion of Functionality from Untrusted Control Sphere
Pin the A2ML validator to an immutable commit.
hyperpolymath/deed-ecosystem/validate-action@mainexecutes mutable upstream code in the CI trust boundary. Replace it with a full 40-character commit SHA and regenerate.github/workflows/actions.lock. Confirm that the pinned revision supports the existingpathandstrictinputs.🤖 Prompt for AI Agents