From aed64c33dbcee20327c315e2f2e57255eb68008d Mon Sep 17 00:00:00 2001 From: ssvoss Date: Fri, 2 Oct 2026 17:37:53 -0400 Subject: [PATCH 1/5] Update GitHub Actions dependencies --- .github/actions/configure-aws-oidc/CHANGELOG.md | 6 ++++++ .github/actions/configure-aws-oidc/action.yml | 2 +- .github/workflows/CHANGELOGS/run_sonar_scan.md | 6 ++++++ .github/workflows/CHANGELOGS/tf_apply.md | 7 +++++++ .../workflows/CHANGELOGS/tf_validate_plan_single_root.md | 7 +++++++ .github/workflows/run_sonar_scan.yml | 2 +- .github/workflows/tf_apply.yml | 4 ++-- .github/workflows/tf_validate_plan_single_root.yml | 4 ++-- 8 files changed, 32 insertions(+), 6 deletions(-) diff --git a/.github/actions/configure-aws-oidc/CHANGELOG.md b/.github/actions/configure-aws-oidc/CHANGELOG.md index 2b0c55b..171f25f 100644 --- a/.github/actions/configure-aws-oidc/CHANGELOG.md +++ b/.github/actions/configure-aws-oidc/CHANGELOG.md @@ -2,6 +2,12 @@ All notable changes to the `configure-aws-oidc` composite action are documented in this file. +## 1.0.2 + +### Changed + +- Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`. + ## 1.0.1 ### Changed diff --git a/.github/actions/configure-aws-oidc/action.yml b/.github/actions/configure-aws-oidc/action.yml index 56f1c69..4af814f 100644 --- a/.github/actions/configure-aws-oidc/action.yml +++ b/.github/actions/configure-aws-oidc/action.yml @@ -53,7 +53,7 @@ runs: ORG_READ_ONLY_SSH_KEY: ${{ inputs.ORG_READ_ONLY_SSH_KEY }} - name: Configure AWS credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ steps.get-role-arn.outputs.role-arn }} aws-region: ${{ steps.get-role-arn.outputs.region }} diff --git a/.github/workflows/CHANGELOGS/run_sonar_scan.md b/.github/workflows/CHANGELOGS/run_sonar_scan.md index d0fbe46..3dd4e97 100644 --- a/.github/workflows/CHANGELOGS/run_sonar_scan.md +++ b/.github/workflows/CHANGELOGS/run_sonar_scan.md @@ -2,6 +2,12 @@ All notable changes to the **run_sonar_scan** callable workflow are documented in this file. +## 1.0.1 + +### Changed + +- Bumped `SonarSource/sonarqube-scan-action` from `v8.2.1` to `v8.3.0`. + ## 1.0.0 ### Added diff --git a/.github/workflows/CHANGELOGS/tf_apply.md b/.github/workflows/CHANGELOGS/tf_apply.md index 8fede11..0ba970d 100644 --- a/.github/workflows/CHANGELOGS/tf_apply.md +++ b/.github/workflows/CHANGELOGS/tf_apply.md @@ -2,6 +2,13 @@ All notable changes to the **tf_apply** reusable workflow are documented in this file. +## 0.0.2 + +### Changed + +- Bumped `OpenSesame/gha-oidc-access/get-role-arn` from the `v2` commit to `v2.0.2`. +- Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`. + ## 0.0.1 ### Added diff --git a/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md b/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md index b927f09..4ad50f1 100644 --- a/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md +++ b/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md @@ -3,6 +3,13 @@ All notable changes to the **tf_validate_plan_single_root** reusable workflow are documented in this file. +## 0.0.2 + +### Changed + +- Bumped `OpenSesame/gha-oidc-access/get-role-arn` from the `v2` commit to `v2.0.2`. +- Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`. + ## 0.0.1 ### Added diff --git a/.github/workflows/run_sonar_scan.yml b/.github/workflows/run_sonar_scan.yml index d9a4fbe..a5640ea 100644 --- a/.github/workflows/run_sonar_scan.yml +++ b/.github/workflows/run_sonar_scan.yml @@ -28,6 +28,6 @@ jobs: fetch-depth: 0 - name: Run SonarQube scan - uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1 + uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/.github/workflows/tf_apply.yml b/.github/workflows/tf_apply.yml index 8d59865..a659b7c 100644 --- a/.github/workflows/tf_apply.yml +++ b/.github/workflows/tf_apply.yml @@ -78,13 +78,13 @@ jobs: steps: - id: get-role-arn - uses: OpenSesame/gha-oidc-access/get-role-arn@1417c02442b956045a6930e271ce134faf8e09e6 # v2 + uses: OpenSesame/gha-oidc-access/get-role-arn@42e851ba54935047834bc50a3e2de800cc4952b9 # v2.0.2 with: domain: ${{ inputs.oidc-domain }} env: ${{ inputs.environment }} ORG_READ_ONLY_SSH_KEY: ${{ secrets.ORG_READ_ONLY_SSH_KEY }} - - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + - uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ steps.get-role-arn.outputs.role-arn }} role-session-name: ${{ inputs.terraform-workspace }}-${{ inputs.environment }}-Run${{ github.run_id }} diff --git a/.github/workflows/tf_validate_plan_single_root.yml b/.github/workflows/tf_validate_plan_single_root.yml index 0cbede3..8f0d137 100644 --- a/.github/workflows/tf_validate_plan_single_root.yml +++ b/.github/workflows/tf_validate_plan_single_root.yml @@ -73,13 +73,13 @@ jobs: steps: - id: get-role-arn - uses: OpenSesame/gha-oidc-access/get-role-arn@1417c02442b956045a6930e271ce134faf8e09e6 # v2 + uses: OpenSesame/gha-oidc-access/get-role-arn@42e851ba54935047834bc50a3e2de800cc4952b9 # v2.0.2 with: domain: ${{ inputs.oidc-domain }} env: ${{ inputs.environment }} ORG_READ_ONLY_SSH_KEY: ${{ secrets.ORG_READ_ONLY_SSH_KEY }} - - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4 + - uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: role-to-assume: ${{ steps.get-role-arn.outputs.role-arn }} role-session-name: ${{ inputs.terraform-workspace }}-${{ inputs.environment }}-Run${{ github.run_id }} From fbcda8d5d72356f946aa2c0d961d0af4b81a7dd1 Mon Sep 17 00:00:00 2001 From: ssvoss Date: Fri, 2 Oct 2026 17:41:13 -0400 Subject: [PATCH 2/5] Automerge major npm dev dependency updates --- renovate.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/renovate.json b/renovate.json index 5a34d36..9c25f8f 100644 --- a/renovate.json +++ b/renovate.json @@ -19,10 +19,10 @@ "platformAutomerge": false, "packageRules": [ { - "description": "Group and automerge npm development dependency non-major updates.", + "description": "Group and automerge all npm development dependency updates.", "matchManagers": ["npm"], "matchDepTypes": ["devDependencies"], - "matchUpdateTypes": ["minor", "patch"], + "matchUpdateTypes": ["major", "minor", "patch"], "groupName": "npm development dependencies", "groupSlug": "npm-dev-dependencies", "addLabels": ["dependencies", "v:untracked"], From 16b5b16dafef2ef66f412f333b4569a7e61a5f71 Mon Sep 17 00:00:00 2001 From: ssvoss Date: Fri, 2 Oct 2026 17:49:47 -0400 Subject: [PATCH 3/5] Upgrade repository tooling to npm 12 --- .github/workflows/internal_on_push_ci.yml | 2 +- AGENTS.md | 2 +- README.md | 2 +- package-lock.json | 2 +- package.json | 4 ++-- 5 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/internal_on_push_ci.yml b/.github/workflows/internal_on_push_ci.yml index 07c0013..bf062b3 100644 --- a/.github/workflows/internal_on_push_ci.yml +++ b/.github/workflows/internal_on_push_ci.yml @@ -26,7 +26,7 @@ jobs: node-version-file: .nvmrc - name: Set up npm - run: npm install --global npm@11.20.0 + run: npm install --global npm@12.1.0 - name: Install dependencies run: npm ci diff --git a/AGENTS.md b/AGENTS.md index 1555de0..d3cf43b 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -6,7 +6,7 @@ the repository map, consumer guidance, and migration context. ## Commands -- Install the pinned npm version: `npm install --global npm@11.20.0` +- Install the pinned npm version: `npm install --global npm@12.1.0` - Install dependencies: `npm ci` - Run all non-mutating checks: `npm run ci` - Run tests in watch mode: `npm run watch` diff --git a/README.md b/README.md index 777f202..8af22d0 100644 --- a/README.md +++ b/README.md @@ -67,7 +67,7 @@ There are recommended vscode extensions and settings included in the project. To get started: - install semgrep globally `brew install semgrep` -- install the pinned npm version `npm install --global npm@11.20.0` +- install the pinned npm version `npm install --global npm@12.1.0` - install project dependencies `npm ci` ### 🏷️ Versioning Policy Overview diff --git a/package-lock.json b/package-lock.json index 53df75c..c474ae1 100644 --- a/package-lock.json +++ b/package-lock.json @@ -21,7 +21,7 @@ }, "engines": { "node": "24.x", - "npm": ">=11.10.0 <12" + "npm": ">=12.1.0 <13" } }, "node_modules/@babel/code-frame": { diff --git a/package.json b/package.json index 2f7199b..0ac534f 100644 --- a/package.json +++ b/package.json @@ -2,7 +2,7 @@ "name": "core-github-actions", "version": "1.0.0", "private": true, - "packageManager": "npm@11.20.0", + "packageManager": "npm@12.1.0", "description": "Core Team's reusable GitHub Actions", "repository": { "type": "git", @@ -12,7 +12,7 @@ "license": "UNLICENSED", "engines": { "node": "24.x", - "npm": ">=11.10.0 <12" + "npm": ">=12.1.0 <13" }, "homepage": "https://github.com/OpenSesame/core-github-actions#readme", "devDependencies": { From 04bdab04b2fc76caa86a27035117971fe83059e9 Mon Sep 17 00:00:00 2001 From: ssvoss Date: Fri, 2 Oct 2026 18:05:31 -0400 Subject: [PATCH 4/5] Pin workflows to Ubuntu 24.04 --- .github/workflows/CHANGELOGS/deploy_environment.md | 7 +++++++ .github/workflows/CHANGELOGS/deploy_thru_prod.md | 7 +++++++ .github/workflows/CHANGELOGS/run_semgrep_scan.md | 6 ++++++ .github/workflows/CHANGELOGS/run_sonar_scan.md | 3 ++- .github/workflows/CHANGELOGS/tf_apply.md | 3 ++- .github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md | 7 +++++++ .../workflows/CHANGELOGS/tf_validate_plan_single_root.md | 3 ++- .github/workflows/CHANGELOGS/trigger_workflow_and_wait.md | 6 ++++++ .github/workflows/READMES/deploy_environment.md | 3 ++- .github/workflows/READMES/deploy_thru_prod.md | 3 ++- .github/workflows/READMES/run_semgrep_scan.md | 2 ++ .github/workflows/READMES/run_sonar_scan.md | 4 +++- .github/workflows/READMES/tf_apply.md | 3 ++- .github/workflows/READMES/tf_validate_plan_env_roots.md | 3 ++- .github/workflows/READMES/tf_validate_plan_single_root.md | 4 ++-- .github/workflows/READMES/trigger_workflow_and_wait.md | 3 ++- .github/workflows/deploy_thru_prod.yml | 6 +++--- .github/workflows/internal_on_merge_tag_versions.yml | 4 ++-- .../internal_on_pr_validate_component_version.yml | 2 +- .github/workflows/internal_on_push_ci.yml | 2 +- .github/workflows/run_semgrep_scan.yml | 2 +- .github/workflows/run_sonar_scan.yml | 2 +- .github/workflows/tf_apply.yml | 4 ++-- .github/workflows/tf_validate_plan_single_root.yml | 2 +- .github/workflows/trigger_workflow_and_wait.yml | 2 +- semgrep/README.md | 2 +- 26 files changed, 70 insertions(+), 25 deletions(-) diff --git a/.github/workflows/CHANGELOGS/deploy_environment.md b/.github/workflows/CHANGELOGS/deploy_environment.md index 379b5dd..6464a6b 100644 --- a/.github/workflows/CHANGELOGS/deploy_environment.md +++ b/.github/workflows/CHANGELOGS/deploy_environment.md @@ -2,6 +2,13 @@ All notable changes to the **deploy_environment** reusable workflow are documented in this file. +## 0.1.0 + +### Changed + +- Pinned the composed Terraform plan and apply jobs to Ubuntu 24.04 for a stable, versioned runner + contract. + ## 0.0.1 ### Added diff --git a/.github/workflows/CHANGELOGS/deploy_thru_prod.md b/.github/workflows/CHANGELOGS/deploy_thru_prod.md index c97a59b..100c8de 100644 --- a/.github/workflows/CHANGELOGS/deploy_thru_prod.md +++ b/.github/workflows/CHANGELOGS/deploy_thru_prod.md @@ -2,6 +2,13 @@ All notable changes to the **deploy_thru_prod** reusable workflow are documented in this file. +## 0.1.0 + +### Changed + +- Pinned the workflow's jobs and composed environment-deployment chain to Ubuntu 24.04 for a + stable, versioned runner contract. + ## 0.0.1 ### Added diff --git a/.github/workflows/CHANGELOGS/run_semgrep_scan.md b/.github/workflows/CHANGELOGS/run_semgrep_scan.md index bb0649f..982c4d7 100644 --- a/.github/workflows/CHANGELOGS/run_semgrep_scan.md +++ b/.github/workflows/CHANGELOGS/run_semgrep_scan.md @@ -2,6 +2,12 @@ All notable changes to the **run_semgrep_scan** callable workflow are documented in this file. +## 1.1.0 + +### Changed + +- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract. + ## 1.0.4 ### Changed diff --git a/.github/workflows/CHANGELOGS/run_sonar_scan.md b/.github/workflows/CHANGELOGS/run_sonar_scan.md index 3dd4e97..81004b2 100644 --- a/.github/workflows/CHANGELOGS/run_sonar_scan.md +++ b/.github/workflows/CHANGELOGS/run_sonar_scan.md @@ -2,10 +2,11 @@ All notable changes to the **run_sonar_scan** callable workflow are documented in this file. -## 1.0.1 +## 1.1.0 ### Changed +- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract. - Bumped `SonarSource/sonarqube-scan-action` from `v8.2.1` to `v8.3.0`. ## 1.0.0 diff --git a/.github/workflows/CHANGELOGS/tf_apply.md b/.github/workflows/CHANGELOGS/tf_apply.md index 0ba970d..26f06d8 100644 --- a/.github/workflows/CHANGELOGS/tf_apply.md +++ b/.github/workflows/CHANGELOGS/tf_apply.md @@ -2,10 +2,11 @@ All notable changes to the **tf_apply** reusable workflow are documented in this file. -## 0.0.2 +## 0.1.0 ### Changed +- Pinned workflow jobs to Ubuntu 24.04 for a stable, versioned runner contract. - Bumped `OpenSesame/gha-oidc-access/get-role-arn` from the `v2` commit to `v2.0.2`. - Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`. diff --git a/.github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md b/.github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md index 2069694..a2e74a9 100644 --- a/.github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md +++ b/.github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md @@ -3,6 +3,13 @@ All notable changes to the **tf_validate_plan_env_roots** reusable workflow are documented in this file. +## 0.1.0 + +### Changed + +- Pinned the composed environment plan jobs to Ubuntu 24.04 for a stable, versioned runner + contract. + ## 0.0.1 ### Added diff --git a/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md b/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md index 4ad50f1..4b2f154 100644 --- a/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md +++ b/.github/workflows/CHANGELOGS/tf_validate_plan_single_root.md @@ -3,10 +3,11 @@ All notable changes to the **tf_validate_plan_single_root** reusable workflow are documented in this file. -## 0.0.2 +## 0.1.0 ### Changed +- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract. - Bumped `OpenSesame/gha-oidc-access/get-role-arn` from the `v2` commit to `v2.0.2`. - Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`. diff --git a/.github/workflows/CHANGELOGS/trigger_workflow_and_wait.md b/.github/workflows/CHANGELOGS/trigger_workflow_and_wait.md index 919238c..08c4e80 100644 --- a/.github/workflows/CHANGELOGS/trigger_workflow_and_wait.md +++ b/.github/workflows/CHANGELOGS/trigger_workflow_and_wait.md @@ -3,6 +3,12 @@ All notable changes to the **trigger_workflow_and_wait** reusable workflow are documented in this file. +## 0.1.0 + +### Changed + +- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract. + ## 0.0.1 ### Added diff --git a/.github/workflows/READMES/deploy_environment.md b/.github/workflows/READMES/deploy_environment.md index 64d1736..993daaf 100644 --- a/.github/workflows/READMES/deploy_environment.md +++ b/.github/workflows/READMES/deploy_environment.md @@ -20,7 +20,7 @@ successful plan. ```yaml jobs: deploy-dev: - uses: OpenSesame/core-github-actions/.github/workflows/deploy_environment.yml@workflows/deploy_environment/0.0.1 + uses: OpenSesame/core-github-actions/.github/workflows/deploy_environment.yml@workflows/deploy_environment/0.1.0 with: environment: dev commit-identifier: ${{ github.sha }} @@ -61,6 +61,7 @@ jobs: Runs for the same repository and environment share a concurrency group. The workflow declares `id-token: write` and `contents: read` permissions for its called workflows. +The composed plan and apply jobs run on Ubuntu 24.04. ## Contribution diff --git a/.github/workflows/READMES/deploy_thru_prod.md b/.github/workflows/READMES/deploy_thru_prod.md index f83db6a..80ca78f 100644 --- a/.github/workflows/READMES/deploy_thru_prod.md +++ b/.github/workflows/READMES/deploy_thru_prod.md @@ -20,7 +20,7 @@ GitHub release, and posts the final stage, prod, and release status to the assoc ```yaml jobs: deploy-through-prod: - uses: OpenSesame/core-github-actions/.github/workflows/deploy_thru_prod.yml@workflows/deploy_thru_prod/0.0.1 + uses: OpenSesame/core-github-actions/.github/workflows/deploy_thru_prod.yml@workflows/deploy_thru_prod/0.1.0 with: commit-identifier: ${{ github.sha }} oidc-domain: core @@ -63,6 +63,7 @@ The release-tag job only runs when the caller's event is a merged pull request o the same repository share one concurrency group. The workflow requests `id-token: write`, `contents: write`, and `pull-requests: write` permissions. +Its direct and composed jobs run on Ubuntu 24.04. ## Contribution diff --git a/.github/workflows/READMES/run_semgrep_scan.md b/.github/workflows/READMES/run_semgrep_scan.md index 0ea2c4e..e04d443 100644 --- a/.github/workflows/READMES/run_semgrep_scan.md +++ b/.github/workflows/READMES/run_semgrep_scan.md @@ -58,6 +58,8 @@ The workflow provides the following outputs for use in downstream jobs or for re Findings are also posted as PR comments and Reviewdog annotations (if enabled), and a summary is written to the GitHub Actions job summary. +The workflow job runs on Ubuntu 24.04. + ## Contribution - Update the workflow file and related javascript file diff --git a/.github/workflows/READMES/run_sonar_scan.md b/.github/workflows/READMES/run_sonar_scan.md index 45762fa..0be8347 100644 --- a/.github/workflows/READMES/run_sonar_scan.md +++ b/.github/workflows/READMES/run_sonar_scan.md @@ -11,7 +11,7 @@ The consuming repository must include its SonarQube configuration, such as a `so ```yaml jobs: sonar-scan: - uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.0.0 + uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.1.0 secrets: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} ``` @@ -35,6 +35,8 @@ with: | ------------- | -------- | ---------------------------------------------- | | `SONAR_TOKEN` | Yes | Token used to authenticate the SonarQube scan. | +The workflow job runs on Ubuntu 24.04. + ## Contribution - Update the workflow, README, and changelog together. diff --git a/.github/workflows/READMES/tf_apply.md b/.github/workflows/READMES/tf_apply.md index b6a8f57..01fabbe 100644 --- a/.github/workflows/READMES/tf_apply.md +++ b/.github/workflows/READMES/tf_apply.md @@ -19,7 +19,7 @@ GitHub environment and Terraform workspace. ```yaml jobs: terraform-apply: - uses: OpenSesame/core-github-actions/.github/workflows/tf_apply.yml@workflows/tf_apply/0.0.1 + uses: OpenSesame/core-github-actions/.github/workflows/tf_apply.yml@workflows/tf_apply/0.1.0 with: environment: dev oidc-domain: core @@ -65,6 +65,7 @@ jobs: The apply job sets `TF_VAR_IACDeploymentRef` to the current Actions run URL and `TF_VAR_release_name` to `release-tag`. Runs for the same repository and environment share a concurrency group. The workflow requests `id-token: write` and `contents: read` permissions. +Both workflow jobs run on Ubuntu 24.04. ## Contribution diff --git a/.github/workflows/READMES/tf_validate_plan_env_roots.md b/.github/workflows/READMES/tf_validate_plan_env_roots.md index 8161119..edaef89 100644 --- a/.github/workflows/READMES/tf_validate_plan_env_roots.md +++ b/.github/workflows/READMES/tf_validate_plan_env_roots.md @@ -19,7 +19,7 @@ workflow. ```yaml jobs: terraform-plans: - uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_env_roots.yml@workflows/tf_validate_plan_env_roots/0.0.1 + uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_env_roots.yml@workflows/tf_validate_plan_env_roots/0.1.0 with: commit-identifier: ${{ github.sha }} oidc-domain: core @@ -54,6 +54,7 @@ jobs: - Uses the supplied `terraform-workspace` for every environment when present; otherwise uses the environment name. - Does not request plan artifacts from the called workflow. +- Runs the composed plan jobs on Ubuntu 24.04. ## Contribution diff --git a/.github/workflows/READMES/tf_validate_plan_single_root.md b/.github/workflows/READMES/tf_validate_plan_single_root.md index 6e63a9a..6546c02 100644 --- a/.github/workflows/READMES/tf_validate_plan_single_root.md +++ b/.github/workflows/READMES/tf_validate_plan_single_root.md @@ -20,7 +20,7 @@ optionally upload the rendered plan as an artifact. ```yaml jobs: terraform-plan: - uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_single_root.yml@workflows/tf_validate_plan_single_root/0.0.1 + uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_single_root.yml@workflows/tf_validate_plan_single_root/0.1.0 with: environment: dev oidc-domain: core @@ -80,7 +80,7 @@ When enabled, artifact upload looks for `terraform//tfplan.txt`, re 8. Optionally uploads the rendered plan text for seven days. Runs for the same repository and environment share a concurrency group. The job requests -`id-token: write` and `contents: read` permissions. +`id-token: write` and `contents: read` permissions and runs on Ubuntu 24.04. ## Contribution diff --git a/.github/workflows/READMES/trigger_workflow_and_wait.md b/.github/workflows/READMES/trigger_workflow_and_wait.md index 99a3e56..a538e91 100644 --- a/.github/workflows/READMES/trigger_workflow_and_wait.md +++ b/.github/workflows/READMES/trigger_workflow_and_wait.md @@ -19,7 +19,7 @@ the resulting run, waits for completion, and exposes the downstream run details ```yaml jobs: downstream: - uses: OpenSesame/core-github-actions/.github/workflows/trigger_workflow_and_wait.yml@workflows/trigger_workflow_and_wait/0.0.1 + uses: OpenSesame/core-github-actions/.github/workflows/trigger_workflow_and_wait.yml@workflows/trigger_workflow_and_wait/0.1.0 with: owner: OpenSesame repo: example-service @@ -68,6 +68,7 @@ jobs: Run discovery selects the newest run ID that appears after dispatch. The completion polling loop has no independent maximum duration; it waits as long as the downstream run remains incomplete. The workflow requests `id-token: write` and `contents: read` permissions in the caller repository. +The workflow job runs on Ubuntu 24.04. ## Contribution diff --git a/.github/workflows/deploy_thru_prod.yml b/.github/workflows/deploy_thru_prod.yml index 6eae617..756eda5 100644 --- a/.github/workflows/deploy_thru_prod.yml +++ b/.github/workflows/deploy_thru_prod.yml @@ -47,7 +47,7 @@ permissions: jobs: Set-Release-Tag: - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 if: ${{ github.event.pull_request.merged || github.event_name == 'workflow_dispatch' }} outputs: release-tag: ${{ steps.releaseTag.outputs.release-tag }} @@ -108,7 +108,7 @@ jobs: CreateRelease: name: Create New Release needs: [Set-Release-Tag, DeployProd] - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Checkout Actions @@ -126,7 +126,7 @@ jobs: ReportStatus: name: Report Status on PR - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 needs: [DeployDev, DeployStage, DeployProd, CreateRelease] if: always() env: diff --git a/.github/workflows/internal_on_merge_tag_versions.yml b/.github/workflows/internal_on_merge_tag_versions.yml index 27f899c..5100b71 100644 --- a/.github/workflows/internal_on_merge_tag_versions.yml +++ b/.github/workflows/internal_on_merge_tag_versions.yml @@ -11,7 +11,7 @@ permissions: jobs: no-merge: if: github.event.pull_request.merged == false - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: No Merge Detected run: | @@ -21,7 +21,7 @@ jobs: set-version-tags: if: github.event.pull_request.merged == true - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/.github/workflows/internal_on_pr_validate_component_version.yml b/.github/workflows/internal_on_pr_validate_component_version.yml index 0665e10..4c69d68 100644 --- a/.github/workflows/internal_on_pr_validate_component_version.yml +++ b/.github/workflows/internal_on_pr_validate_component_version.yml @@ -18,7 +18,7 @@ permissions: jobs: validate-version-labels: name: Validate PR Version Labels - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Checkout repo diff --git a/.github/workflows/internal_on_push_ci.yml b/.github/workflows/internal_on_push_ci.yml index bf062b3..0659c54 100644 --- a/.github/workflows/internal_on_push_ci.yml +++ b/.github/workflows/internal_on_push_ci.yml @@ -14,7 +14,7 @@ permissions: jobs: internal-ci: name: Internal CI - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Checkout repo diff --git a/.github/workflows/run_semgrep_scan.yml b/.github/workflows/run_semgrep_scan.yml index 72ed66b..4781022 100644 --- a/.github/workflows/run_semgrep_scan.yml +++ b/.github/workflows/run_semgrep_scan.yml @@ -125,7 +125,7 @@ concurrency: jobs: semgrep: name: Run Semgrep - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 outputs: total_findings: ${{ steps.semgrep.outputs.totalFindings }} diff --git a/.github/workflows/run_sonar_scan.yml b/.github/workflows/run_sonar_scan.yml index a5640ea..f2239d1 100644 --- a/.github/workflows/run_sonar_scan.yml +++ b/.github/workflows/run_sonar_scan.yml @@ -18,7 +18,7 @@ permissions: jobs: sonar-scan: name: Run SonarQube scan - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Checkout diff --git a/.github/workflows/tf_apply.yml b/.github/workflows/tf_apply.yml index a659b7c..05ee0fb 100644 --- a/.github/workflows/tf_apply.yml +++ b/.github/workflows/tf_apply.yml @@ -51,7 +51,7 @@ env: jobs: Summary: - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Markdown Summary run: | @@ -67,7 +67,7 @@ jobs: TF-Apply: name: Terraform Apply - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 environment: ${{ inputs.environment}} defaults: run: diff --git a/.github/workflows/tf_validate_plan_single_root.yml b/.github/workflows/tf_validate_plan_single_root.yml index 8f0d137..6c6a6e5 100644 --- a/.github/workflows/tf_validate_plan_single_root.yml +++ b/.github/workflows/tf_validate_plan_single_root.yml @@ -63,7 +63,7 @@ env: jobs: TF-Validate-Plan: name: Terraform Validate and Plan ${{ inputs.environment }} - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 environment: ${{ inputs.environment }} defaults: # runs all steps in this directory run: diff --git a/.github/workflows/trigger_workflow_and_wait.yml b/.github/workflows/trigger_workflow_and_wait.yml index c5b648f..f5e0c47 100644 --- a/.github/workflows/trigger_workflow_and_wait.yml +++ b/.github/workflows/trigger_workflow_and_wait.yml @@ -44,7 +44,7 @@ permissions: jobs: trigger: - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 outputs: downstream_run_id: ${{ steps.run.outputs.downstream_run_id }} downstream_html_url: ${{ steps.run.outputs.downstream_html_url }} diff --git a/semgrep/README.md b/semgrep/README.md index c2d6a62..3e88a9a 100644 --- a/semgrep/README.md +++ b/semgrep/README.md @@ -143,7 +143,7 @@ permissions: jobs: security: - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - name: Checkout code uses: actions/checkout@v4 From 575fee1774429968f25c0d5cae31e3c89db5f87a Mon Sep 17 00:00:00 2001 From: ssvoss Date: Fri, 2 Oct 2026 18:11:48 -0400 Subject: [PATCH 5/5] Require Node 24.15 for npm 12 --- .nvmrc | 2 +- AGENTS.md | 1 + README.md | 1 + package-lock.json | 2 +- package.json | 2 +- 5 files changed, 5 insertions(+), 3 deletions(-) diff --git a/.nvmrc b/.nvmrc index cabf43b..5bf4400 100644 --- a/.nvmrc +++ b/.nvmrc @@ -1 +1 @@ -24 \ No newline at end of file +24.15.0 diff --git a/AGENTS.md b/AGENTS.md index d3cf43b..b160423 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -6,6 +6,7 @@ the repository map, consumer guidance, and migration context. ## Commands +- Use Node.js 24.15.0 or newer in the Node.js 24 release line: `nvm use` - Install the pinned npm version: `npm install --global npm@12.1.0` - Install dependencies: `npm ci` - Run all non-mutating checks: `npm run ci` diff --git a/README.md b/README.md index 8af22d0..bab8185 100644 --- a/README.md +++ b/README.md @@ -67,6 +67,7 @@ There are recommended vscode extensions and settings included in the project. To get started: - install semgrep globally `brew install semgrep` +- use Node.js 24.15.0 or newer in the Node.js 24 release line (`nvm use`) - install the pinned npm version `npm install --global npm@12.1.0` - install project dependencies `npm ci` diff --git a/package-lock.json b/package-lock.json index c474ae1..e089010 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20,7 +20,7 @@ "semgrep": "0.0.1" }, "engines": { - "node": "24.x", + "node": ">=24.15.0 <25", "npm": ">=12.1.0 <13" } }, diff --git a/package.json b/package.json index 0ac534f..dd92b0a 100644 --- a/package.json +++ b/package.json @@ -11,7 +11,7 @@ "author": "Core Services Team @ OpenSesame", "license": "UNLICENSED", "engines": { - "node": "24.x", + "node": ">=24.15.0 <25", "npm": ">=12.1.0 <13" }, "homepage": "https://github.com/OpenSesame/core-github-actions#readme",