Skip to content
This repository was archived by the owner on Oct 9, 2026. It is now read-only.

ci: add CI and OSV scan, locked with gh actions-lock - #1

Merged
lmdexpr merged 5 commits into
mainfrom
ci/osv-scan
Oct 1, 2026
Merged

lmdexpr merged 5 commits into
mainfrom
ci/osv-scan

Conversation

@lmdexpr

@lmdexpr lmdexpr commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Summary

  • OSV scan (.github/workflows/osv.yml): scan dune.lock/ against OSV.dev with lmdexpr/dune-lock-osv on lock changes and daily. Scheduled runs open/update an issue when vulnerabilities are found.
  • CI (.github/workflows/ci.yml): build and dune runtest (with the aws-c-auth submodule fixtures) on Linux and macOS via ocaml-dune/setup-dune, pinned to dune 3.23.1 to match local; format check with the ocamlformat dev tool (dune build @fmt).
  • Lock: all workflow dependencies, including transitive ones from composite actions (actions/github-script, actions/cache, actions/upload-artifact), are pinned in .github/workflows/actions.lock by gh actions-lock (technical preview, v0.1.6).

Notes

  • gh actions-lock rewrites uses: to tag/branch refs (e.g. lmdexpr/dune-lock-osv@main); the commit SHA is pinned in the lockfile. Run gh actions-lock to update it.
  • Verified locally: gh actions-lock --no-fix (valid), actionlint, dune build @fmt, dune runtest.

🤖 Generated with Claude Code

lmdexpr and others added 2 commits October 1, 2026 17:16
Run lmdexpr/dune-lock-osv on dune.lock changes and daily (scheduled runs
open/update an issue when vulnerabilities are found). Workflow
dependencies, including the transitive actions/github-script, are locked
with gh actions-lock (technical preview, v0.1.6).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Build and run the test suite (with the aws-c-auth fixtures) on Linux and
macOS using dune package management, pinned to dune 3.23.1, and check
formatting with the ocamlformat dev tool. Dependencies are locked with
gh actions-lock.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@lmdexpr lmdexpr self-assigned this Oct 1, 2026
Relock against the latest opam-repository to pick up fixes reported by
OSV.dev:

- cohttp 6.2.1 -> 6.3.0 (OSEC-2026-16)
- cstruct 6.2.0 -> 6.3.0 (OSEC-2026-20)
- ocaml 5.4.1 -> 5.5.1 (OSEC-2026-05, OSEC-2026-18)

Also bumps digestif 1.3.1, eio 1.6, http 6.3.0 and mtime 2.2.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
lmdexpr and others added 2 commits October 1, 2026 17:47
The standalone fmt job took ~10 minutes: @fmt needs the locked compiler, so it
rebuilt the project's compiler on top of the ocamlformat dev tool, and its
dune cache never saved because it raced the Linux test job on the same key.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Install dune 3.24.2 in CI (setup-dune) and relock with it. dune 3.24 adds
opam-repository-relocatable to the default repositories; the only package
change is dune-configurator 3.23.1 -> 3.24.2. The dune-project language
level stays at 3.23 so opam users are not forced onto dune 3.24.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@lmdexpr
lmdexpr merged commit 18b21b6 into main Oct 1, 2026
4 of 5 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant