github / github/gh-actions-lock
`gh actions-lock` CLI and GitHub Actions Runner Disagree on Moved Repo Resolution
- Dominant language
- Go
- Stars
- 49
- Forks
- 3
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 3
Description
## Problem
An existing workflow file points to a repo that was moved (new location: `typesafegithub/github-actions-typing`):
```yaml
uses: krzema12/github-actions-typing@9ddf35b71a482be7d8922b28e8d00df16b77e315 # v2.2.2
```
After running `gh action-lock`:
```
$ gh actions-lock
✓ Migrated 1 local action to `$/…`
✓ Pinned 5 actions across 1 workflow
step-security/harden-runner@v2.20.1 (b09bb98)
└─ .github/workflows/ci.yaml
actions/checkout@v7.0.1 (3d3c42e)
└─ .github/workflows/ci.yaml
actions/setup-node@v7.0.0 (8207627)
└─ .github/workflows/ci.yaml
krzema12/github-actions-typing@v2.2.2 (9ddf35b)
└─ .github/workflows/ci.yaml
fsfe/reuse-action@v6.0.0 (676e2d5)
└─ .github/workflows/ci.yaml
Resolution record: /home/user/.cache/gh-actions-lock/logs/run-20260813-174743.955.json
```
The old repo name is still retained:
```yaml
uses: krzema12/github-actions-typing@v2.2.2
```
However, the GitHub Action runner fails:
> Error: lockfile verification did not produce a result for this action. lockfile verification did not produce a result for this action. Unable to resolve action `krzema12/github-actions-typing`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile
Running `gh actions-lock` as suggested results in a positive feedback with no file changes:
```
$ gh actions-lock
✓ All 1 workflow valid
Resolution record: /home/user/.cache/gh-actions-lock/logs/run-20260813-175025.037.json
```
Example PR: https://github.com/achrinza/setup-db2/pull/309
Full failed GitHub Actions run log
```
2026-08-13T09:59:13.3600826Z Current runner version: '2.336.0'
2026-08-13T09:59:13.3627406Z ##[group]Runner Image Provisioner
2026-08-13T09:59:13.3628393Z Hosted Compute Agent
2026-08-13T09:59:13.3628984Z Version: 20260707.563
2026-08-13T09:59:13.3629618Z Commit: 02667638d2b423fbc733a8e32a88b44996a3ba6e
2026-08-13T09:59:13.3630415Z Build Date: 2026-07-07T19:33:50Z
2026-08-13T09:59:13.3631093Z Worker ID: {fc7855a9-5976-48d1-aa5f-6bdd691dc73d}
2026-08-13T09:59:13.3631824Z Azure Region: westus
2026-08-13T09:59:13.3632389Z ##[endgroup]
2026-08-13T09:59:13.3634726Z ##[group]Operating System
2026-08-13T09:59:13.3635488Z Ubuntu
2026-08-13T09:59:13.3636016Z 24.04.4
2026-08-13T09:59:13.3636504Z LTS
2026-08-13T09:59:13.3637076Z ##[endgroup]
2026-08-13T09:59:13.3637654Z ##[group]Runner Image
2026-08-13T09:59:13.3638273Z Image: ubuntu-24.04
2026-08-13T09:59:13.3638854Z Version: 20260720.247.2
2026-08-13T09:59:13.3640150Z Included Software: https://github.com/actions/runner-images/blob/ubuntu24/20260720.247/images/ubuntu/Ubuntu2404-Readme.md
2026-08-13T09:59:13.3641663Z Image Release: https://github.com/actions/runner-images/releases/tag/ubuntu24%2F20260720.247
2026-08-13T09:59:13.3642848Z ##[endgroup]
2026-08-13T09:59:13.3643837Z ##[group]GITHUB_TOKEN Permissions
2026-08-13T09:59:13.3646196Z Metadata: read
2026-08-13T09:59:13.3646840Z ##[endgroup]
2026-08-13T09:59:13.3648998Z Secret source: Actions
2026-08-13T09:59:13.3650589Z Using locked action versions from the workflow's lockfile
2026-08-13T09:59:13.3651519Z Prepare workflow directory
2026-08-13T09:59:13.3997518Z Prepare all required actions
2026-08-13T09:59:13.4049498Z Getting action download info
2026-08-13T09:59:13.7833925Z ##[error]lockfile verification did not produce a result for this action. lockfile verification did not produce a result for this action. Unable to resolve action `krzema12/github-actions-typing`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile
```
run-20260813-174743.955.json
```json
{
"schema": "run-record/v1",
"generated_at": "2026-08-13T09:47:43Z",
"tool": {
"name": "gh-actions-lock",
"version": "v0.1.6"
},
"repo": {
"owner": "achrinza",
"name": "setup-db2",
"host": "github.com"
},
"summary": {
"workflows": 1,
"actions": 5,
"valid": true,
"pinned": 5,
"already_pinned": 0,
"full_scan": 0,
"needs_investigation": 0,
"skipped": 0,
"unresolved": 0
},
"actions": [
{
"nwo": "step-security/harden-runner",
"ref": "v2.20.1",
"sha": "b09bb98e06d4d774595224525879c09bc6e98c40",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "actions/checkout",
"ref": "v7.0.1",
"sha": "3d3c42e5aac5ba805825da76410c181273ba90b1",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "actions/setup-node",
"ref": "v7.0.0",
"sha": "820762786026740c76f36085b0efc47a31fe5020",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "krzema12/github-actions-typing",
"ref": "v2.2.2",
"sha": "9ddf35b71a482be7d8922b28e8d00df16b77e315",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
},
{
"nwo": "fsfe/reuse-action",
"ref": "v6.0.0",
"sha": "676e2d560c9a403aa252096d99fcab3e1132b0f5",
"resolution": "pinned",
"workflows": [
".github/workflows/ci.yaml"
],
"direct": true
}
]
}
```
With pinned hashes, a moved repo did not matter since the hash remained the same and the redirect is followed. However, the lockfile also tracks the more-immutable `owner_id`.
## Workaround
Manually update `uses` to the new repo name and then regenerate the lockfile with `gh actions-lock`.
## Expected Outcome
1. `gh actions-lock` should replace `uses` with the new repo name.
2. `gh actions-lock` lockfile validation should fail when referencing the moved repo's old location, thereby agreeing with the GitHub Action Runner.
Contributor guide
Research direction
Start with the gh actions-lock command and reproduce the case using .github/workflows/ci.yaml, where the moved krzema12/github-actions-typing action remains after locking. Compare the resolver's handling of the old and new repository names with the GitHub Actions runner error and the recorded owner_id. Done means the command updates uses to the new location and validation rejects the old location consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, go
- Domain
- ci-cd, cli, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100