Skip to content

actions.lock: security-scan.yml's reusable panic-attack ref is out of sync (lock-sync gate red on main) #295

Description

@hyperpolymath

actions.lock is in sync with the workflow YAML (scripts/check-lock-sync.sh) is red on main:

gh actions-lock (default, --no-narrow, --no-migrate-local-actions, --relock --rescan) does not update job-level reusable-workflow refs; the script's own remediation text says this record must be corrected by hand. Hand edits to actions.lock are denied to agents on this estate, so this needs a human edit, or a fix to gh actions-lock.

Acceptance criteria

  • The lock's security-scan.yml entry and dependencies: record name the same panic-attack SHA that security-scan.yml pins.
  • ./scripts/check-lock-sync.sh exits 0 on main.
  • gh actions-lock --no-fix still exits 0.

Found while working #294.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaves incorrectlycicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions