diff --git a/.github/actions/vantio-prove/action.yml b/.github/actions/vantio-prove/action.yml index 2d32d0e2..4500a79f 100644 --- a/.github/actions/vantio-prove/action.yml +++ b/.github/actions/vantio-prove/action.yml @@ -17,7 +17,7 @@ runs: using: composite steps: - name: Setup Node - uses: actions/setup-node@v4 + uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 with: node-version: "22" @@ -41,7 +41,7 @@ runs: fi - name: Upload proof - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: vantio-proof path: ${{ inputs.working-directory }}/${{ inputs.output-path }} diff --git a/docs/programs/release-engineering/00-INVENTORY.md b/docs/programs/release-engineering/00-INVENTORY.md index c0c9bbc5..159caa60 100644 --- a/docs/programs/release-engineering/00-INVENTORY.md +++ b/docs/programs/release-engineering/00-INVENTORY.md @@ -39,9 +39,9 @@ Python wheel `vantio_agent_sdk-3.1.0-py3-none-any.whl` is pinned at 39235 bytes, - Root `packageManager` names pnpm `11.13.0` and carries a `sha512` integrity string. - `pnpm-lock.yaml` is present. Its SHA-256 is in the pin report. Lockfile importers record resolved versions for the workspace dependency ranges. - `scripts/release/stage_sealed_pypi.py` pins the Python 3.1.0 filenames, byte lengths, and SHA-256 values. Dispatch inputs cannot replace them. -- Workflow files under `.github/workflows/` pin third-party actions to commit SHAs with tag comments. The pin report records those as `owner/name@sha # tag` with `digest_pinned: true`. `.github/actions/vantio-prove/action.yml` still uses floating `@v4` refs, and those two stay `digest_pinned: false`. +- Workflow files under `.github/workflows/` and the local composite `.github/actions/vantio-prove/action.yml` pin third-party actions to commit SHAs with tag comments. The pin report records those as `owner/name@sha # tag` with `digest_pinned: true`. - `packages/vantio-agent-sdk-py/pyproject.toml` requires `hatchling` with no version comparator. -- CI and the provenance workflow install with `pnpm install --frozen-lockfile`. That binds the install to the lockfile. The local composite action refs and the Python build backend stay unpinned. +- CI and the provenance workflow install with `pnpm install --frozen-lockfile`. That binds the install to the lockfile. The Python build backend stays unpinned. `npm-publish.yml`, `pypi-publish.yml`, and `mcp-registry-publish.yml` trigger on `workflow_dispatch`. `ci.yml` triggers on push and builds candidate artifacts. The candidate job packs and builds. It performs no registry write. diff --git a/docs/programs/release-engineering/dossiers/optics-public.json b/docs/programs/release-engineering/dossiers/optics-public.json index 35d20801..34ed60c0 100644 --- a/docs/programs/release-engineering/dossiers/optics-public.json +++ b/docs/programs/release-engineering/dossiers/optics-public.json @@ -56,20 +56,6 @@ "name": "cli-tarball", "required_for_publish": true, "value": "UNRECORDED" - }, - { - "accepted_as_pin": false, - "kind": "unpinned", - "name": ".github/actions/vantio-prove/action.yml actions/setup-node@v4", - "required_for_publish": true, - "value": "actions/setup-node@v4" - }, - { - "accepted_as_pin": false, - "kind": "unpinned", - "name": ".github/actions/vantio-prove/action.yml actions/upload-artifact@v4", - "required_for_publish": true, - "value": "actions/upload-artifact@v4" } ], "private_distribution": { @@ -90,7 +76,7 @@ "builds": [], "formal_claim": false, "reasons": [ - "Workflow third-party actions are commit SHA pins with tag comments. The local composite .github/actions/vantio-prove still uses floating @v4 refs.", + "All tip third-party action uses in workflows and the local composite .github/actions/vantio-prove are commit SHA pins with tag comments.", "The Python build-system requirement is hatchling with no version comparator.", "No second build digest is recorded in this force." ], diff --git a/docs/programs/release-engineering/generated/evaluations.json b/docs/programs/release-engineering/generated/evaluations.json index 3bf4a2ca..795c1622 100644 --- a/docs/programs/release-engineering/generated/evaluations.json +++ b/docs/programs/release-engineering/generated/evaluations.json @@ -10,7 +10,7 @@ "release_success": false, "requirements": [ { - "detail": "pin python-build-hatchling is unpinned; pin node-toolchain is unpinned; pin cli-tarball is unrecorded; pin .github/actions/vantio-prove/action.yml actions/setup-node@v4 is unpinned; pin .github/actions/vantio-prove/action.yml actions/upload-artifact@v4 is unpinned", + "detail": "pin python-build-hatchling is unpinned; pin node-toolchain is unpinned; pin cli-tarball is unrecorded", "id": "R1", "status": "GAP" }, diff --git a/docs/programs/release-engineering/generated/pin-report.json b/docs/programs/release-engineering/generated/pin-report.json index 044b1d54..ae0dd176 100644 --- a/docs/programs/release-engineering/generated/pin-report.json +++ b/docs/programs/release-engineering/generated/pin-report.json @@ -1,14 +1,14 @@ { "actions": [ { - "digest_pinned": false, + "digest_pinned": true, "file": ".github/actions/vantio-prove/action.yml", - "uses": "actions/setup-node@v4" + "uses": "actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4" }, { - "digest_pinned": false, + "digest_pinned": true, "file": ".github/actions/vantio-prove/action.yml", - "uses": "actions/upload-artifact@v4" + "uses": "actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4" }, { "digest_pinned": true, diff --git a/scripts/release/ws11/characterize.mjs b/scripts/release/ws11/characterize.mjs index 348cd031..59bc184f 100644 --- a/scripts/release/ws11/characterize.mjs +++ b/scripts/release/ws11/characterize.mjs @@ -193,7 +193,7 @@ export function characterizeOptics(root, inventory = buildInventory(root)) { ...actionPins, ], reproducibility: assessment([ - "Workflow third-party actions are commit SHA pins with tag comments. The local composite .github/actions/vantio-prove still uses floating @v4 refs.", + "All tip third-party action uses in workflows and the local composite .github/actions/vantio-prove are commit SHA pins with tag comments.", "The Python build-system requirement is hatchling with no version comparator.", "No second build digest is recorded in this force.", ]), diff --git a/scripts/release/ws11/ws11.test.mjs b/scripts/release/ws11/ws11.test.mjs index 6dc939b4..1d65e9a3 100644 --- a/scripts/release/ws11/ws11.test.mjs +++ b/scripts/release/ws11/ws11.test.mjs @@ -277,7 +277,7 @@ test("actionUses keeps SHA pins that carry a tag comment", () => { ]); }); -test("pin report records SHA-pinned workflow actions and the sealed Python hashes", () => { +test("pin report records SHA-pinned workflow and composite actions and the sealed Python hashes", () => { const { artifacts } = allGenerated(ROOT); const report = artifacts["pin-report.json"]; assert.equal(report.package_manager.name, "pnpm"); @@ -287,10 +287,7 @@ test("pin report records SHA-pinned workflow actions and the sealed Python hashe const pinned = report.actions.filter((action) => action.digest_pinned === true); assert.deepEqual( floating.map((action) => `${action.file} ${action.uses}`), - [ - ".github/actions/vantio-prove/action.yml actions/setup-node@v4", - ".github/actions/vantio-prove/action.yml actions/upload-artifact@v4", - ], + [], ); assert.ok(pinned.length > 0); assert.equal(pinned.length, report.actions.length - floating.length);