actions.lock is in sync with the workflow YAML (scripts/check-lock-sync.sh) is red on main:
gh actions-lock (default, --no-narrow, --no-migrate-local-actions, --relock --rescan) does not update job-level reusable-workflow refs; the script's own remediation text says this record must be corrected by hand. Hand edits to actions.lock are denied to agents on this estate, so this needs a human edit, or a fix to gh actions-lock.
Acceptance criteria
Found while working #294.
🤖 Generated with Claude Code
actions.lock is in sync with the workflow YAML(scripts/check-lock-sync.sh) is red onmain:.github/workflows/security-scan.ymlcallshyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@5e75753…(and Dependabot PR chore(deps): bump hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml from 5e7575340961a21098d8d9600461038897016a4d to acdb9821a67fe0a275b39f1b388be364df7fbd4a in the actions group #294 bumps it to@acdb982…)..github/workflows/security-scan.ymlkey and itsdependencies:record still namehyperpolymath/panic-attack@27b3d93….gh actions-lock(default,--no-narrow,--no-migrate-local-actions,--relock --rescan) does not update job-level reusable-workflow refs; the script's own remediation text says this record must be corrected by hand. Hand edits toactions.lockare denied to agents on this estate, so this needs a human edit, or a fix togh actions-lock.Acceptance criteria
security-scan.ymlentry anddependencies:record name the samepanic-attackSHA thatsecurity-scan.ymlpins../scripts/check-lock-sync.shexits 0 onmain.gh actions-lock --no-fixstill exits 0.Found while working #294.
🤖 Generated with Claude Code