github / github/gh-actions-lock

`gh actions-lock` CLI and GitHub Actions Runner Disagree on Moved Repo Resolution

Open
#110 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
49
Forks
3
Avg merge
1d 20h
Merged PRs (30d)
3

Description

## Problem

An existing workflow file points to a repo that was moved (new location: `typesafegithub/github-actions-typing`):

```yaml
uses: krzema12/github-actions-typing@9ddf35b71a482be7d8922b28e8d00df16b77e315 # v2.2.2
```

After running `gh action-lock`:

```
$ gh actions-lock
✓ Migrated 1 local action to `$/…`

✓ Pinned 5 actions across 1 workflow
step-security/harden-runner@v2.20.1 (b09bb98)
└─ .github/workflows/ci.yaml
actions/checkout@v7.0.1 (3d3c42e)
└─ .github/workflows/ci.yaml
actions/setup-node@v7.0.0 (8207627)
└─ .github/workflows/ci.yaml
krzema12/github-actions-typing@v2.2.2 (9ddf35b)
└─ .github/workflows/ci.yaml
fsfe/reuse-action@v6.0.0 (676e2d5)
└─ .github/workflows/ci.yaml

Resolution record: /home/user/.cache/gh-actions-lock/logs/run-20260813-174743.955.json
```

The old repo name is still retained:

```yaml
uses: krzema12/github-actions-typing@v2.2.2
```

However, the GitHub Action runner fails:

> Error: lockfile verification did not produce a result for this action. lockfile verification did not produce a result for this action. Unable to resolve action `krzema12/github-actions-typing`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile

Running `gh actions-lock` as suggested results in a positive feedback with no file changes:

```
$ gh actions-lock

✓ All 1 workflow valid

Resolution record: /home/user/.cache/gh-actions-lock/logs/run-20260813-175025.037.json
```

Example PR: https://github.com/achrinza/setup-db2/pull/309

Full failed GitHub Actions run log

```
2026-08-13T09:59:13.3600826Z Current runner version: '2.336.0'
2026-08-13T09:59:13.3627406Z ##[group]Runner Image Provisioner
2026-08-13T09:59:13.3628393Z Hosted Compute Agent
2026-08-13T09:59:13.3628984Z Version: 20260707.563
2026-08-13T09:59:13.3629618Z Commit: 02667638d2b423fbc733a8e32a88b44996a3ba6e
2026-08-13T09:59:13.3630415Z Build Date: 2026-07-07T19:33:50Z
2026-08-13T09:59:13.3631093Z Worker ID: {fc7855a9-5976-48d1-aa5f-6bdd691dc73d}
2026-08-13T09:59:13.3631824Z Azure Region: westus
2026-08-13T09:59:13.3632389Z ##[endgroup]
2026-08-13T09:59:13.3634726Z ##[group]Operating System
2026-08-13T09:59:13.3635488Z Ubuntu
2026-08-13T09:59:13.3636016Z 24.04.4
2026-08-13T09:59:13.3636504Z LTS
2026-08-13T09:59:13.3637076Z ##[endgroup]
2026-08-13T09:59:13.3637654Z ##[group]Runner Image
2026-08-13T09:59:13.3638273Z Image: ubuntu-24.04
2026-08-13T09:59:13.3638854Z Version: 20260720.247.2
2026-08-13T09:59:13.3640150Z Included Software: https://github.com/actions/runner-images/blob/ubuntu24/20260720.247/images/ubuntu/Ubuntu2404-Readme.md
2026-08-13T09:59:13.3641663Z Image Release: https://github.com/actions/runner-images/releases/tag/ubuntu24%2F20260720.247
2026-08-13T09:59:13.3642848Z ##[endgroup]
2026-08-13T09:59:13.3643837Z ##[group]GITHUB_TOKEN Permissions
2026-08-13T09:59:13.3646196Z Metadata: read
2026-08-13T09:59:13.3646840Z ##[endgroup]
2026-08-13T09:59:13.3648998Z Secret source: Actions
2026-08-13T09:59:13.3650589Z Using locked action versions from the workflow's lockfile
2026-08-13T09:59:13.3651519Z Prepare workflow directory
2026-08-13T09:59:13.3997518Z Prepare all required actions
2026-08-13T09:59:13.4049498Z Getting action download info
2026-08-13T09:59:13.7833925Z ##[error]lockfile verification did not produce a result for this action. lockfile verification did not produce a result for this action. Unable to resolve action `krzema12/github-actions-typing`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile
```

run-20260813-174743.955.json

```json
{
"schema": "run-record/v1",
"generated_at": "2026-08-13T09:47:43Z",
"tool": {
"name": "gh-actions-lock",
"version": "v0.1.6"
},
"repo": {
"owner": "achrinza",
"name": "setup-db2",
"host": "github.com"
},
"summary": {
"workflows": 1,
"actions": 5,
"valid": true,
"pinned": 5,
"already_pinned": 0,
"full_scan": 0,
"needs_investigation": 0,
"skipped": 0,
"unresolved": 0
},
"actions": [
{
"nwo": "step-security/harden-runner",
"ref": "v2.20.1",
"sha": "b09bb98e06d4d774595224525879c09bc6e98c40",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "actions/checkout",
"ref": "v7.0.1",
"sha": "3d3c42e5aac5ba805825da76410c181273ba90b1",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "actions/setup-node",
"ref": "v7.0.0",
"sha": "820762786026740c76f36085b0efc47a31fe5020",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "krzema12/github-actions-typing",
"ref": "v2.2.2",
"sha": "9ddf35b71a482be7d8922b28e8d00df16b77e315",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "fsfe/reuse-action",
"ref": "v6.0.0",
"sha": "676e2d560c9a403aa252096d99fcab3e1132b0f5",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
}
]
}
```

With pinned hashes, a moved repo did not matter since the hash remained the same and the redirect is followed. However, the lockfile also tracks the more-immutable `owner_id`.

## Workaround

Manually update `uses` to the new repo name and then regenerate the lockfile with `gh actions-lock`.

## Expected Outcome

1. `gh actions-lock` should replace `uses` with the new repo name.
2. `gh actions-lock` lockfile validation should fail when referencing the moved repo's old location, thereby agreeing with the GitHub Action Runner.

Contributor guide

Open the contributing guide

Research direction

Start with the gh actions-lock command and reproduce the case using .github/workflows/ci.yaml, where the moved krzema12/github-actions-typing action remains after locking. Compare the resolver's handling of the old and new repository names with the GitHub Actions runner error and the recorded owner_id. Done means the command updates uses to the new location and validation rejects the old location consistently.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, go
Domain
ci-cd, cli, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.