Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/deploy_environment.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the **deploy_environment** reusable workflow are documented in this file.

## 0.2.0

### Changed

- Updated the composed Terraform plan and apply jobs from Ubuntu 24.04 to Ubuntu 26.04.

## 0.1.0

### Changed
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/CHANGELOGS/deploy_thru_prod.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,13 @@

All notable changes to the **deploy_thru_prod** reusable workflow are documented in this file.

## 0.2.0

### Changed

- Updated the workflow's jobs and composed environment-deployment chain from Ubuntu 24.04 to
Ubuntu 26.04.

## 0.1.0

### Changed
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/run_semgrep_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the **run_semgrep_scan** callable workflow are documented in this file.

## 1.2.0

### Changed

- Updated the workflow job from Ubuntu 24.04 to Ubuntu 26.04.

## 1.1.0

### Changed
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/run_sonar_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the **run_sonar_scan** callable workflow are documented in this file.

## 1.2.0

### Changed

- Updated the workflow job from Ubuntu 24.04 to Ubuntu 26.04.

## 1.1.0

### Changed
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/tf_apply.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@

All notable changes to the **tf_apply** reusable workflow are documented in this file.

## 0.2.0

### Changed

- Updated workflow jobs from Ubuntu 24.04 to Ubuntu 26.04.

## 0.1.0

### Changed
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/tf_validate_plan_env_roots.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@
All notable changes to the **tf_validate_plan_env_roots** reusable workflow are documented in this
file.

## 0.2.0

### Changed

- Updated the composed environment plan jobs from Ubuntu 24.04 to Ubuntu 26.04.

## 0.1.0

### Changed
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@
All notable changes to the **tf_validate_plan_single_root** reusable workflow are documented in
this file.

## 0.2.0

### Changed

- Updated the workflow job from Ubuntu 24.04 to Ubuntu 26.04.

## 0.1.0

### Changed
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/CHANGELOGS/trigger_workflow_and_wait.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@
All notable changes to the **trigger_workflow_and_wait** reusable workflow are documented in this
file.

## 0.2.0

### Changed

- Updated the workflow job from Ubuntu 24.04 to Ubuntu 26.04.

## 0.1.0

### Changed
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/deploy_environment.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ successful plan.
```yaml
jobs:
deploy-dev:
uses: OpenSesame/core-github-actions/.github/workflows/deploy_environment.yml@workflows/deploy_environment/0.1.0
uses: OpenSesame/core-github-actions/.github/workflows/deploy_environment.yml@workflows/deploy_environment/0.2.0
with:
environment: dev
commit-identifier: ${{ github.sha }}
Expand Down Expand Up @@ -61,7 +61,7 @@ jobs:

Runs for the same repository and environment share a concurrency group. The workflow declares
`id-token: write` and `contents: read` permissions for its called workflows.
The composed plan and apply jobs run on Ubuntu 24.04.
The composed plan and apply jobs run on Ubuntu 26.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/deploy_thru_prod.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ GitHub release, and posts the final stage, prod, and release status to the assoc
```yaml
jobs:
deploy-through-prod:
uses: OpenSesame/core-github-actions/.github/workflows/deploy_thru_prod.yml@workflows/deploy_thru_prod/0.1.0
uses: OpenSesame/core-github-actions/.github/workflows/deploy_thru_prod.yml@workflows/deploy_thru_prod/0.2.0
with:
commit-identifier: ${{ github.sha }}
oidc-domain: core
Expand Down Expand Up @@ -63,7 +63,7 @@ The release-tag job only runs when the caller's event is a merged pull request o
the same repository share one concurrency group.

The workflow requests `id-token: write`, `contents: write`, and `pull-requests: write` permissions.
Its direct and composed jobs run on Ubuntu 24.04.
Its direct and composed jobs run on Ubuntu 26.04.

## Contribution

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/READMES/run_semgrep_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ The workflow provides the following outputs for use in downstream jobs or for re

Findings are also posted as PR comments and Reviewdog annotations (if enabled), and a summary is written to the GitHub Actions job summary.

The workflow job runs on Ubuntu 24.04.
The workflow job runs on Ubuntu 26.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/run_sonar_scan.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ The consuming repository must include its SonarQube configuration, such as a `so
```yaml
jobs:
sonar-scan:
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.1.0
uses: OpenSesame/core-github-actions/.github/workflows/run_sonar_scan.yml@workflows/run_sonar_scan/1.2.0
secrets:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
```
Expand All @@ -35,7 +35,7 @@ with:
| ------------- | -------- | ---------------------------------------------- |
| `SONAR_TOKEN` | Yes | Token used to authenticate the SonarQube scan. |

The workflow job runs on Ubuntu 24.04.
The workflow job runs on Ubuntu 26.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/tf_apply.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ GitHub environment and Terraform workspace.
```yaml
jobs:
terraform-apply:
uses: OpenSesame/core-github-actions/.github/workflows/tf_apply.yml@workflows/tf_apply/0.1.0
uses: OpenSesame/core-github-actions/.github/workflows/tf_apply.yml@workflows/tf_apply/0.2.0
with:
environment: dev
oidc-domain: core
Expand Down Expand Up @@ -65,7 +65,7 @@ jobs:
The apply job sets `TF_VAR_IACDeploymentRef` to the current Actions run URL and
`TF_VAR_release_name` to `release-tag`. Runs for the same repository and environment share a
concurrency group. The workflow requests `id-token: write` and `contents: read` permissions.
Both workflow jobs run on Ubuntu 24.04.
Both workflow jobs run on Ubuntu 26.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/tf_validate_plan_env_roots.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ workflow.
```yaml
jobs:
terraform-plans:
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_env_roots.yml@workflows/tf_validate_plan_env_roots/0.1.0
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_env_roots.yml@workflows/tf_validate_plan_env_roots/0.2.0
with:
commit-identifier: ${{ github.sha }}
oidc-domain: core
Expand Down Expand Up @@ -54,7 +54,7 @@ jobs:
- Uses the supplied `terraform-workspace` for every environment when present; otherwise uses the
environment name.
- Does not request plan artifacts from the called workflow.
- Runs the composed plan jobs on Ubuntu 24.04.
- Runs the composed plan jobs on Ubuntu 26.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/tf_validate_plan_single_root.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ optionally upload the rendered plan as an artifact.
```yaml
jobs:
terraform-plan:
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_single_root.yml@workflows/tf_validate_plan_single_root/0.1.0
uses: OpenSesame/core-github-actions/.github/workflows/tf_validate_plan_single_root.yml@workflows/tf_validate_plan_single_root/0.2.0
with:
environment: dev
oidc-domain: core
Expand Down Expand Up @@ -80,7 +80,7 @@ When enabled, artifact upload looks for `terraform/<environment>/tfplan.txt`, re
8. Optionally uploads the rendered plan text for seven days.

Runs for the same repository and environment share a concurrency group. The job requests
`id-token: write` and `contents: read` permissions and runs on Ubuntu 24.04.
`id-token: write` and `contents: read` permissions and runs on Ubuntu 26.04.

## Contribution

Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/READMES/trigger_workflow_and_wait.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ the resulting run, waits for completion, and exposes the downstream run details
```yaml
jobs:
downstream:
uses: OpenSesame/core-github-actions/.github/workflows/trigger_workflow_and_wait.yml@workflows/trigger_workflow_and_wait/0.1.0
uses: OpenSesame/core-github-actions/.github/workflows/trigger_workflow_and_wait.yml@workflows/trigger_workflow_and_wait/0.2.0
with:
owner: OpenSesame
repo: example-service
Expand Down Expand Up @@ -68,7 +68,7 @@ jobs:
Run discovery selects the newest run ID that appears after dispatch. The completion polling loop has
no independent maximum duration; it waits as long as the downstream run remains incomplete. The
workflow requests `id-token: write` and `contents: read` permissions in the caller repository.
The workflow job runs on Ubuntu 24.04.
The workflow job runs on Ubuntu 26.04.

## Contribution

Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/deploy_thru_prod.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ permissions:

jobs:
Set-Release-Tag:
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
if: ${{ github.event.pull_request.merged || github.event_name == 'workflow_dispatch' }}
outputs:
release-tag: ${{ steps.releaseTag.outputs.release-tag }}
Expand Down Expand Up @@ -108,7 +108,7 @@ jobs:
CreateRelease:
name: Create New Release
needs: [Set-Release-Tag, DeployProd]
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04

steps:
- name: Checkout Actions
Expand All @@ -126,7 +126,7 @@ jobs:

ReportStatus:
name: Report Status on PR
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
needs: [DeployDev, DeployStage, DeployProd, CreateRelease]
if: always()
env:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/internal_on_merge_tag_versions.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ permissions:
jobs:
no-merge:
if: github.event.pull_request.merged == false
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: No Merge Detected
run: |
Expand All @@ -21,7 +21,7 @@ jobs:

set-version-tags:
if: github.event.pull_request.merged == true
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ permissions:
jobs:
validate-version-labels:
name: Validate PR Version Labels
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04

steps:
- name: Checkout repo
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/internal_on_push_ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ permissions:
jobs:
internal-ci:
name: Internal CI
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04

steps:
- name: Checkout repo
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/run_semgrep_scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ concurrency:
jobs:
semgrep:
name: Run Semgrep
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04

outputs:
total_findings: ${{ steps.semgrep.outputs.totalFindings }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/run_sonar_scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ permissions:
jobs:
sonar-scan:
name: Run SonarQube scan
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04

steps:
- name: Checkout
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/tf_apply.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ env:

jobs:
Summary:
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Markdown Summary
run: |
Expand All @@ -67,7 +67,7 @@ jobs:

TF-Apply:
name: Terraform Apply
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
environment: ${{ inputs.environment}}
defaults:
run:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/tf_validate_plan_single_root.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ env:
jobs:
TF-Validate-Plan:
name: Terraform Validate and Plan ${{ inputs.environment }}
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
environment: ${{ inputs.environment }}
defaults: # runs all steps in this directory
run:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/trigger_workflow_and_wait.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ permissions:

jobs:
trigger:
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
outputs:
downstream_run_id: ${{ steps.run.outputs.downstream_run_id }}
downstream_html_url: ${{ steps.run.outputs.downstream_html_url }}
Expand Down
2 changes: 1 addition & 1 deletion .nvmrc
Original file line number Diff line number Diff line change
@@ -1 +1 @@
24.15.0
24.21.0
2 changes: 1 addition & 1 deletion semgrep/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@ permissions:

jobs:
security:
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@v4
Expand Down
Loading