Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/actions/configure-aws-oidc/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the `configure-aws-oidc` composite action are documented in this file.

## 1.0.2

### Changed

- Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`.

## 1.0.1

### Changed
Expand Down
2 changes: 1 addition & 1 deletion .github/actions/configure-aws-oidc/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ runs:
ORG_READ_ONLY_SSH_KEY: ${{ inputs.ORG_READ_ONLY_SSH_KEY }}

- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
role-to-assume: ${{ steps.get-role-arn.outputs.role-arn }}
aws-region: ${{ steps.get-role-arn.outputs.region }}
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/CHANGELOGS/deploy_environment.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,13 @@

All notable changes to the **deploy_environment** reusable workflow are documented in this file.

## 0.1.0

### Changed

- Pinned the composed Terraform plan and apply jobs to Ubuntu 24.04 for a stable, versioned runner
contract.

## 0.0.1

### Added
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/CHANGELOGS/deploy_thru_prod.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,13 @@

All notable changes to the **deploy_thru_prod** reusable workflow are documented in this file.

## 0.1.0

### Changed

- Pinned the workflow's jobs and composed environment-deployment chain to Ubuntu 24.04 for a
stable, versioned runner contract.

## 0.0.1

### Added
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/run_semgrep_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the **run_semgrep_scan** callable workflow are documented in this file.

## 1.1.0

### Changed

- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract.

## 1.0.4

### Changed
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/CHANGELOGS/run_sonar_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,13 @@

All notable changes to the **run_sonar_scan** callable workflow are documented in this file.

## 1.1.0

### Changed

- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract.
- Bumped `SonarSource/sonarqube-scan-action` from `v8.2.1` to `v8.3.0`.

## 1.0.0

### Added
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/CHANGELOGS/tf_apply.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,14 @@

All notable changes to the **tf_apply** reusable workflow are documented in this file.

## 0.1.0

### Changed

- Pinned workflow jobs to Ubuntu 24.04 for a stable, versioned runner contract.
- Bumped `OpenSesame/gha-oidc-access/get-role-arn` from the `v2` commit to `v2.0.2`.
- Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`.

## 0.0.1

### Added
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,13 @@
All notable changes to the **tf_validate_plan_env_roots** reusable workflow are documented in this
file.

## 0.1.0

### Changed

- Pinned the composed environment plan jobs to Ubuntu 24.04 for a stable, versioned runner
contract.

## 0.0.1

### Added
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,14 @@
All notable changes to the **tf_validate_plan_single_root** reusable workflow are documented in
this file.

## 0.1.0

### Changed

- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract.
- Bumped `OpenSesame/gha-oidc-access/get-role-arn` from the `v2` commit to `v2.0.2`.
- Bumped `aws-actions/configure-aws-credentials` from `v6.2.4` to `v6.3.0`.

## 0.0.1

### Added
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/trigger_workflow_and_wait.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@
All notable changes to the **trigger_workflow_and_wait** reusable workflow are documented in this
file.

## 0.1.0

### Changed

- Pinned the workflow job to Ubuntu 24.04 for a stable, versioned runner contract.

## 0.0.1

### Added
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/READMES/deploy_environment.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ successful plan.
```yaml
jobs:
deploy-dev:
uses: OpenSesame/core-github-actions/.github/workflows/deploy_environment.yml@workflows/deploy_environment/0.0.1
uses: OpenSesame/core-github-actions/.github/workflows/deploy_environment.yml@workflows/deploy_environment/0.1.0
with:
environment: dev
commit-identifier: ${{ github.sha }}
Expand Down Expand Up @@ -61,6 +61,7 @@ jobs:

Runs for the same repository and environment share a concurrency group. The workflow declares
`id-token: write` and `contents: read` permissions for its called workflows.
The composed plan and apply jobs run on Ubuntu 24.04.

## Contribution

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/READMES/deploy_thru_prod.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ GitHub release, and posts the final stage, prod, and release status to the assoc
```yaml
jobs:
deploy-through-prod:
uses: OpenSesame/core-github-actions/.github/workflows/deploy_thru_prod.yml@workflows/deploy_thru_prod/0.0.1
uses: OpenSesame/core-github-actions/.github/workflows/deploy_thru_prod.yml@workflows/deploy_thru_prod/0.1.0
with:
commit-identifier: ${{ github.sha }}
oidc-domain: core
Expand Down Expand Up @@ -63,6 +63,7 @@ The release-tag job only runs when the caller's event is a merged pull request o
the same repository share one concurrency group.

The workflow requests `id-token: write`, `contents: write`, and `pull-requests: write` permissions.
Its direct and composed jobs run on Ubuntu 24.04.

## Contribution

Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/READMES/run_semgrep_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,8 @@ The workflow provides the following outputs for use in downstream jobs or for re

Findings are also posted as PR comments and Reviewdog annotations (if enabled), and a summary is written to the GitHub Actions job summary.

The workflow job runs on Ubuntu 24.04.

## Contribution

- Update the workflow file and related javascript file
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/READMES/run_sonar_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ The consuming repository must include its SonarQube configuration, such as a `so
```yaml
jobs:
sonar-scan:
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.0.0
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.1.0
secrets:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
```
Expand All @@ -35,6 +35,8 @@ with:
| ------------- | -------- | ---------------------------------------------- |
| `SONAR_TOKEN` | Yes | Token used to authenticate the SonarQube scan. |

The workflow job runs on Ubuntu 24.04.

## Contribution

- Update the workflow, README, and changelog together.
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/READMES/tf_apply.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ GitHub environment and Terraform workspace.
```yaml
jobs:
terraform-apply:
uses: OpenSesame/core-github-actions/.github/workflows/tf_apply.yml@workflows/tf_apply/0.0.1
uses: OpenSesame/core-github-actions/.github/workflows/tf_apply.yml@workflows/tf_apply/0.1.0
with:
environment: dev
oidc-domain: core
Expand Down Expand Up @@ -65,6 +65,7 @@ jobs:
The apply job sets `TF_VAR_IACDeploymentRef` to the current Actions run URL and
`TF_VAR_release_name` to `release-tag`. Runs for the same repository and environment share a
concurrency group. The workflow requests `id-token: write` and `contents: read` permissions.
Both workflow jobs run on Ubuntu 24.04.

## Contribution

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/READMES/tf_validate_plan_env_roots.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ workflow.
```yaml
jobs:
terraform-plans:
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_env_roots.yml@workflows/tf_validate_plan_env_roots/0.0.1
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_env_roots.yml@workflows/tf_validate_plan_env_roots/0.1.0
with:
commit-identifier: ${{ github.sha }}
oidc-domain: core
Expand Down Expand Up @@ -54,6 +54,7 @@ jobs:
- Uses the supplied `terraform-workspace` for every environment when present; otherwise uses the
environment name.
- Does not request plan artifacts from the called workflow.
- Runs the composed plan jobs on Ubuntu 24.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/tf_validate_plan_single_root.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ optionally upload the rendered plan as an artifact.
```yaml
jobs:
terraform-plan:
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_single_root.yml@workflows/tf_validate_plan_single_root/0.0.1
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_single_root.yml@workflows/tf_validate_plan_single_root/0.1.0
with:
environment: dev
oidc-domain: core
Expand Down Expand Up @@ -80,7 +80,7 @@ When enabled, artifact upload looks for `terraform/<environment>/tfplan.txt`, re
8. Optionally uploads the rendered plan text for seven days.

Runs for the same repository and environment share a concurrency group. The job requests
`id-token: write` and `contents: read` permissions.
`id-token: write` and `contents: read` permissions and runs on Ubuntu 24.04.

## Contribution

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/READMES/trigger_workflow_and_wait.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ the resulting run, waits for completion, and exposes the downstream run details
```yaml
jobs:
downstream:
uses: OpenSesame/core-github-actions/.github/workflows/trigger_workflow_and_wait.yml@workflows/trigger_workflow_and_wait/0.0.1
uses: OpenSesame/core-github-actions/.github/workflows/trigger_workflow_and_wait.yml@workflows/trigger_workflow_and_wait/0.1.0
with:
owner: OpenSesame
repo: example-service
Expand Down Expand Up @@ -68,6 +68,7 @@ jobs:
Run discovery selects the newest run ID that appears after dispatch. The completion polling loop has
no independent maximum duration; it waits as long as the downstream run remains incomplete. The
workflow requests `id-token: write` and `contents: read` permissions in the caller repository.
The workflow job runs on Ubuntu 24.04.

## Contribution

Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/deploy_thru_prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ permissions:

jobs:
Set-Release-Tag:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
if: ${{ github.event.pull_request.merged || github.event_name == 'workflow_dispatch' }}
outputs:
release-tag: ${{ steps.releaseTag.outputs.release-tag }}
Expand Down Expand Up @@ -108,7 +108,7 @@ jobs:
CreateRelease:
name: Create New Release
needs: [Set-Release-Tag, DeployProd]
runs-on: ubuntu-latest
runs-on: ubuntu-24.04

steps:
- name: Checkout Actions
Expand All @@ -126,7 +126,7 @@ jobs:

ReportStatus:
name: Report Status on PR
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
needs: [DeployDev, DeployStage, DeployProd, CreateRelease]
if: always()
env:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/internal_on_merge_tag_versions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ permissions:
jobs:
no-merge:
if: github.event.pull_request.merged == false
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
steps:
- name: No Merge Detected
run: |
Expand All @@ -21,7 +21,7 @@ jobs:

set-version-tags:
if: github.event.pull_request.merged == true
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ permissions:
jobs:
validate-version-labels:
name: Validate PR Version Labels
runs-on: ubuntu-latest
runs-on: ubuntu-24.04

steps:
- name: Checkout repo
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/internal_on_push_ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ permissions:
jobs:
internal-ci:
name: Internal CI
runs-on: ubuntu-latest
runs-on: ubuntu-24.04

steps:
- name: Checkout repo
Expand All @@ -26,7 +26,7 @@ jobs:
node-version-file: .nvmrc

- name: Set up npm
run: npm install --global npm@11.20.0
run: npm install --global npm@12.1.0

- name: Install dependencies
run: npm ci
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/run_semgrep_scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ concurrency:
jobs:
semgrep:
name: Run Semgrep
runs-on: ubuntu-latest
runs-on: ubuntu-24.04

outputs:
total_findings: ${{ steps.semgrep.outputs.totalFindings }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/run_sonar_scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ permissions:
jobs:
sonar-scan:
name: Run SonarQube scan
runs-on: ubuntu-latest
runs-on: ubuntu-24.04

steps:
- name: Checkout
Expand All @@ -28,6 +28,6 @@ jobs:
fetch-depth: 0

- name: Run SonarQube scan
uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1
uses: SonarSource/sonarqube-scan-action@d209202bc7d53ff1cc128f7f907dac145c9d6ae9 # v8.3.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
8 changes: 4 additions & 4 deletions .github/workflows/tf_apply.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ env:

jobs:
Summary:
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
steps:
- name: Markdown Summary
run: |
Expand All @@ -67,7 +67,7 @@ jobs:

TF-Apply:
name: Terraform Apply
runs-on: ubuntu-latest
runs-on: ubuntu-24.04
environment: ${{ inputs.environment}}
defaults:
run:
Expand All @@ -78,13 +78,13 @@ jobs:

steps:
- id: get-role-arn
uses: OpenSesame/gha-oidc-access/get-role-arn@1417c02442b956045a6930e271ce134faf8e09e6 # v2
uses: OpenSesame/gha-oidc-access/get-role-arn@42e851ba54935047834bc50a3e2de800cc4952b9 # v2.0.2
with:
domain: ${{ inputs.oidc-domain }}
env: ${{ inputs.environment }}
ORG_READ_ONLY_SSH_KEY: ${{ secrets.ORG_READ_ONLY_SSH_KEY }}

- uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6.2.4
- uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
role-to-assume: ${{ steps.get-role-arn.outputs.role-arn }}
role-session-name: ${{ inputs.terraform-workspace }}-${{ inputs.environment }}-Run${{ github.run_id }}
Expand Down
Loading
Loading