diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a83fe158..179fea02 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -39,13 +39,13 @@ jobs: GOTOOLCHAIN: go1.26.8 steps: - name: Check out source - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.sha }} persist-credentials: false - name: Set up Go - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -84,13 +84,13 @@ jobs: GOTOOLCHAIN: go1.26.8 steps: - name: Check out source - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.sha }} persist-credentials: false - name: Set up Go - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -115,13 +115,13 @@ jobs: OFFLINE_EXPERIMENT_MODULE: ${{ matrix.module }} steps: - name: Check out source - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.sha }} persist-credentials: false - name: Set up Go - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false @@ -139,13 +139,13 @@ jobs: GOTOOLCHAIN: go1.26.8 steps: - name: Check out source - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.sha }} persist-credentials: false - name: Set up Go - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/.github/workflows/pr-fast.yml b/.github/workflows/pr-fast.yml index 4563167c..718baf4c 100644 --- a/.github/workflows/pr-fast.yml +++ b/.github/workflows/pr-fast.yml @@ -22,7 +22,7 @@ jobs: GOTOOLCHAIN: go1.26.8 steps: - name: Check out source - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ github.event.pull_request.head.sha }} fetch-depth: 0 @@ -56,7 +56,7 @@ jobs: - name: Set up Go if: steps.scope.outputs.go == 'true' - uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod cache: false diff --git a/docs/DEPENDENCIES.md b/docs/DEPENDENCIES.md index 45dd32c0..9317f247 100644 --- a/docs/DEPENDENCIES.md +++ b/docs/DEPENDENCIES.md @@ -1,6 +1,6 @@ # Dependency and license inventory -Checked 2026-09-07 for the G03 bootstrap. The runtime module intentionally has no third-party Go dependencies yet, so no `go.sum` is needed. Future implementation issues must add every runtime module to the table and keep `make deps` and `make licenses` passing. +Checked 2026-09-26 for the G03 bootstrap. The runtime module intentionally has no third-party Go dependencies yet, so no `go.sum` is needed. Future implementation issues must add every runtime module to the table and keep `make deps` and `make licenses` passing. ## Runtime modules @@ -33,8 +33,17 @@ Action refs are immutable commit pins. The version labels are recorded for human | Action | Immutable ref | License | Source | | --- | --- | --- | --- | -| `actions/checkout` | `11bd71901bbe5b1630ceea73d27597364c9af683` (`v4.2.2`) | MIT | [action repository](https://github.com/actions/checkout). | -| `actions/setup-go` | `d35c59abb061a4a6fb18e82ac0862c26744d6ab5` (`v5.5.0`) | MIT | [action repository](https://github.com/actions/setup-go). | +| `actions/checkout` | `3d3c42e5aac5ba805825da76410c181273ba90b1` (`v7.0.1`) | MIT | [manifest at pin](https://github.com/actions/checkout/blob/3d3c42e5aac5ba805825da76410c181273ba90b1/action.yml), [release](https://github.com/actions/checkout/releases/tag/v7.0.1), [license at pin](https://github.com/actions/checkout/blob/3d3c42e5aac5ba805825da76410c181273ba90b1/LICENSE). | +| `actions/setup-go` | `b7ad1dad31e06c5925ef5d2fc7ad053ef454303e` (`v7.0.0`) | MIT | [manifest at pin](https://github.com/actions/setup-go/blob/b7ad1dad31e06c5925ef5d2fc7ad053ef454303e/action.yml), [release](https://github.com/actions/setup-go/releases/tag/v7.0.0), [license at pin](https://github.com/actions/setup-go/blob/b7ad1dad31e06c5925ef5d2fc7ad053ef454303e/LICENSE). | + +Both immutable manifests declare `runs.using: node24`; the upstream action +documentation lists Actions Runner `v2.327.1` or later as the Node 24 minimum. +The workflows stay on GitHub-hosted `ubuntu-24.04`. Setup Go v7's ESM migration +does not change its inputs or behavior. The workflow keeps `go-version-file: +go.mod`, the Go 1.26.8 declaration and `GOTOOLCHAIN=go1.26.8`; `cache: false` +keeps module caching disabled. Checkout keeps the exact triggering SHA for +Public CI, the PR head SHA with `fetch-depth: 0`, and +`persist-credentials: false`. The v7 unsafe fork checkout opt-in remains unset. ## CI-only vulnerability tool diff --git a/scripts/tooling_test.go b/scripts/tooling_test.go index 84170489..63aca05b 100644 --- a/scripts/tooling_test.go +++ b/scripts/tooling_test.go @@ -1787,8 +1787,8 @@ func TestPublicWorkflowCapacityContract(t *testing.T) { } const ( - checkout = "uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683" - setupGo = "uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5" + checkout = "uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1" + setupGo = "uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e" mainHead = "ref: ${{ github.sha }}" ) for _, job := range []string{"root", "race", "offline", "vuln"} {