Skip to content

fix(ci): bump erlef/setup-beam SHA for ubuntu24 runner support#8

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/ci-rsr-and-setup-beam-2026-05-14
May 14, 2026
Merged

fix(ci): bump erlef/setup-beam SHA for ubuntu24 runner support#8
hyperpolymath merged 2 commits into
mainfrom
fix/ci-rsr-and-setup-beam-2026-05-14

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

hypatia-scan.yml: bumps erlef/setup-beam SHA from 2f0cc07b… to fc68ffb9… so ImageOS=ubuntu24 resolves to ubuntu-24.04 (matches the pin in hyperpolymath/hypatia upstream).

🤖 Generated with Claude Code

**hypatia-scan.yml**: bumps `erlef/setup-beam` SHA from `2f0cc07b…` to `fc68ffb9…` so `ImageOS=ubuntu24` resolves to `ubuntu-24.04` (matches the pin in hyperpolymath/hypatia upstream).

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Repairs the corrupted `rsr-antipattern.yml` from the prior commit on this branch. See hyperpolymath/stapeln#34 for the full root-cause writeup — the original sweep built its canonical via `gh api --jq '.content'` piped through PowerShell, but `gh` line-wraps base64 in the terminal pipe, so each chunk was decoded separately and the rejoined file has mid-word line breaks (`# SPDX-License-Id\nentifier:`, `name: RSR A\nnti-Pattern`, etc.). GitHub Actions can't parse the resulting YAML — the workflow completes in 0 seconds with no jobs.

This commit overwrites the file with the correct content, built via raw byte download (`Accept: application/vnd.github.raw`) and `[System.IO.File]::WriteAllBytes` so no pipe ever touches the bytes. Round-trip byte-verified against canonical.
@hyperpolymath
hyperpolymath merged commit e685166 into main May 14, 2026
17 of 21 checks passed
@hyperpolymath
hyperpolymath deleted the fix/ci-rsr-and-setup-beam-2026-05-14 branch May 14, 2026 15:48
hyperpolymath added a commit that referenced this pull request May 16, 2026
The pinned SHAs carried two fixed false-positives:
- k9-validate-action: pedigree brace-counting bug ('missing name'
  on files with a security block before metadata) - fixed in #7.
- a2ml-validate-action: identity-field check on canonical typed /
  *file.a2ml manifests - fixed in #8/#9.

Also adds github-actions to dependabot so action pins stay current.

Co-authored-by: Jonathan D.A. Jewell <67598845+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant