Skip to content
This repository was archived by the owner on Oct 9, 2026. It is now read-only.

ci: add CI and OSV scan, locked with gh actions-lock - #1

Merged
lmdexpr merged 3 commits into
mainfrom
ci/osv-scan
Oct 1, 2026
Merged

lmdexpr merged 3 commits into
mainfrom
ci/osv-scan

Conversation

@lmdexpr

@lmdexpr lmdexpr commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Summary

  • OSV scan (.github/workflows/osv.yml): scan dune.lock/ against OSV.dev with lmdexpr/dune-lock-osv on lock changes and daily. Scheduled runs open/update an issue when vulnerabilities are found.
  • CI (.github/workflows/ci.yml): build and dune runtest on Linux and macOS via ocaml-dune/setup-dune, pinned to dune 3.24.0 to match local; format check with the ocamlformat dev tool (dune build @fmt).
  • Lock: all workflow dependencies, including transitive ones from composite actions (actions/github-script, actions/cache, actions/upload-artifact), are pinned in .github/workflows/actions.lock by gh actions-lock (technical preview).

Same setup as lmdexpr/sigv4.ml#1.

Notes

  • gh actions-lock rewrites uses: to tag/branch refs (e.g. lmdexpr/dune-lock-osv@main); the commit SHA is pinned in the lockfile. Run gh actions-lock to update it.
  • dune.lock already carries the fixed versions (cohttp 6.3.0, cstruct 6.3.0, ocaml 5.5.1); a local osv-scanner 2.5.1 run on the generated SBOM reports no issues.
  • Verified locally: gh actions-lock --no-fix (valid), actionlint, dune build @fmt, dune runtest.

🤖 Generated with Claude Code

Build and run the test suite on Linux and macOS using dune package
management, pinned to dune 3.24.0, and check formatting with the
ocamlformat dev tool. Scan dune.lock with lmdexpr/dune-lock-osv on lock
changes and daily (scheduled runs open/update an issue when
vulnerabilities are found). Workflow dependencies, including transitive
ones from composite actions, are locked with gh actions-lock.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@lmdexpr lmdexpr self-assigned this Oct 1, 2026
lmdexpr and others added 2 commits October 1, 2026 17:50
The standalone fmt job took ~10 minutes: @fmt needs the locked compiler, so it
rebuilt the project's compiler on top of the ocamlformat dev tool, and its
dune cache never saved because it raced the Linux test job on the same key.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
CI pins dune 3.24.0; align the project's language version (and the
generated opam lower bounds) with it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@lmdexpr
lmdexpr merged commit 2574b40 into main Oct 1, 2026
3 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant