Skip to content

Commit 19d2c4c

Browse files
authored
[#patch] fix: issues (#263)
1 parent 37af4b7 commit 19d2c4c

15 files changed

Lines changed: 90 additions & 88 deletions

.github/dependabot.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,6 @@ updates:
55
schedule:
66
interval: monthly
77
time: "12:00"
8-
day: wednesday
98
commit-message:
109
prefix: "[#patch]"
1110
include: scope
@@ -18,7 +17,6 @@ updates:
1817
schedule:
1918
interval: monthly
2019
time: "12:00"
21-
day: sunday
2220
commit-message:
2321
prefix: "[#patch]"
2422
prefix-development: ""

.github/workflows/clean-branch-cache.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ on:
66
default: true
77
runs-on:
88
type: string
9-
default: "ubuntu-latest"
9+
default: 'ubuntu-latest'
1010

1111
jobs:
1212
cleanup:

.github/workflows/docker-build-and-push.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,13 +6,13 @@ on:
66
default: true
77
dockerfile:
88
type: string
9-
default: "Dockerfile"
9+
default: 'Dockerfile'
1010
egress-policy-allowlist:
1111
type: string
12-
default: ""
12+
default: ''
1313
flavor:
1414
type: string
15-
description: "Defines a global behavior for tags"
15+
description: 'Defines a global behavior for tags'
1616
default: |
1717
latest=auto
1818
prefix=
@@ -22,16 +22,16 @@ on:
2222
type: string
2323
platforms:
2424
type: string
25-
default: "linux/amd64,linux/arm64"
25+
default: 'linux/amd64,linux/arm64'
2626
push:
2727
type: boolean
2828
default: false
2929
registry:
3030
type: string
31-
default: ""
31+
default: ''
3232
runs-on:
3333
type: string
34-
default: "ubuntu-latest"
34+
default: 'ubuntu-latest'
3535
tags:
3636
type: string
3737
default: |
@@ -44,7 +44,7 @@ on:
4444
default: true
4545
working-directory:
4646
type: string
47-
default: "."
47+
default: '.'
4848
secrets:
4949
registry-username:
5050
required: true
@@ -159,7 +159,7 @@ jobs:
159159
run: |
160160
echo -n "$(cat ./trivy_results.sarif)" | reviewdog -reporter=github-check -f=sarif -level=warning -diff="git diff FETCH_HEAD"
161161
- name: Upload results
162-
uses: github/codeql-action/upload-sarif@3407610120cd5656b6fc71991415cb50748b9489 # v2.20.1
162+
uses: github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
163163
with:
164164
sarif_file: ${{ inputs.working-directory }}/trivy_results.sarif
165165
category: container-security

.github/workflows/gitleaks.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ on:
66
default: true
77
egress-policy-allowlist:
88
type: string
9-
default: ""
9+
default: ''
1010
runs-on:
1111
type: string
12-
default: "ubuntu-latest"
12+
default: 'ubuntu-latest'
1313

1414
jobs:
1515
gitleaks:

.github/workflows/go-ci.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -9,13 +9,13 @@ on:
99
default: true
1010
egress-policy-allowlist:
1111
type: string
12-
default: ""
12+
default: ''
1313
runs-on:
1414
type: string
15-
default: "ubuntu-latest"
15+
default: 'ubuntu-latest'
1616
working-directory:
1717
type: string
18-
default: "."
18+
default: '.'
1919

2020
jobs:
2121
go-lint:

.github/workflows/go-security-scan.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6,16 +6,16 @@ on:
66
default: true
77
egress-policy-allowlist:
88
type: string
9-
default: ""
9+
default: ''
1010
runs-on:
1111
type: string
12-
default: "ubuntu-latest"
12+
default: 'ubuntu-latest'
1313
upload-sarif:
1414
type: boolean
1515
default: true
1616
working-directory:
1717
type: string
18-
default: "."
18+
default: '.'
1919

2020
jobs:
2121
gosec:
@@ -50,7 +50,7 @@ jobs:
5050
# kics-scan ignore-line
5151
uses: securego/gosec@master
5252
with:
53-
args: "-no-fail -fmt sarif -out ${{ inputs.working-directory }}/gosec-results.sarif ${{ inputs.working-directory }}/..."
53+
args: '-no-fail -fmt sarif -out ${{ inputs.working-directory }}/gosec-results.sarif ${{ inputs.working-directory }}/...'
5454
- uses: reviewdog/action-setup@d8edfce3dd5e1ec6978745e801f9c50b5ef80252 # v1.4.0
5555
- name: Run reviewdog
5656
continue-on-error: true
@@ -59,8 +59,8 @@ jobs:
5959
run: |
6060
echo -n "$(cat ./gosec-results.sarif)" | reviewdog -reporter=github-check -f=sarif -level=error -diff="git diff FETCH_HEAD"
6161
- name: Upload results
62-
uses: github/codeql-action/upload-sarif@3407610120cd5656b6fc71991415cb50748b9489 # v2.20.1
62+
uses: github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
6363
with:
64-
sarif_file: "${{ inputs.working-directory }}/gosec-results.sarif"
64+
sarif_file: '${{ inputs.working-directory }}/gosec-results.sarif'
6565
category: sast
6666
if: ${{ inputs.upload-sarif }}

.github/workflows/infra-security-scan.yml

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6,19 +6,19 @@ on:
66
default: true
77
egress-policy-allowlist:
88
type: string
9-
default: ""
9+
default: ''
1010
enable-comments:
1111
type: boolean
1212
default: true
1313
runs-on:
1414
type: string
15-
default: "ubuntu-latest"
15+
default: 'ubuntu-latest'
1616
upload-sarif:
1717
type: boolean
1818
default: true
1919
working-directory:
2020
type: string
21-
default: "."
21+
default: '.'
2222

2323
jobs:
2424
infra-security-scan:
@@ -62,7 +62,7 @@ jobs:
6262
enable_jobs_summary: true
6363
comments_with_queries: true
6464
- name: Upload SARIF file
65-
uses: github/codeql-action/upload-sarif@3407610120cd5656b6fc71991415cb50748b9489 # v2.20.1
65+
uses: github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
6666
with:
6767
sarif_file: ${{ inputs.working-directory }}/kics_results.sarif
6868
category: devops
@@ -97,8 +97,10 @@ jobs:
9797
fail_level: any
9898
filter_mode: nofilter
9999
tool_name: actionlint
100-
- name: Install the latest version of uv
100+
- name: Install uv
101101
uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6.8.0
102+
with:
103+
enable-cache: true
102104
- name: Run zizmor 🌈
103105
run: |
104106
wget https://raw.githubusercontent.com/notdodo/github-actions/refs/heads/main/zizmor.yml
@@ -113,7 +115,7 @@ jobs:
113115
run: |
114116
echo -n "$(cat ./zizmor_results.sarif)" | reviewdog -reporter=github-check -f=sarif -level=warning -diff="git diff FETCH_HEAD"
115117
- name: Upload SARIF file
116-
uses: github/codeql-action/upload-sarif@3407610120cd5656b6fc71991415cb50748b9489 # v2.20.1
118+
uses: github/codeql-action/upload-sarif@16140ae1a102900babc80a33c44059580f687047 # v4.30.9
117119
with:
118120
sarif_file: zizmor_results.sarif
119121
category: github-actions

.github/workflows/local-auto-tagger-docker-bp.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
1-
name: "Auto Tagger docker image builder and publisher"
1+
name: 'Auto Tagger docker image builder and publisher'
22

33
on:
44
push:
55
tags:
6-
- "auto-tagger-v[0-9]+.[0-9]+.[0-9]+"
6+
- 'auto-tagger-v[0-9]+.[0-9]+.[0-9]+'
77

88
jobs:
99
build-push-docker-image:

.github/workflows/local-auto-tagger.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ on:
66
paths:
77
- .github/workflows/*.yml
88
- auto-tagger/**
9-
- "!.github/workflows/local-*.yml"
9+
- '!.github/workflows/local-*.yml'
1010

1111
concurrency:
1212
group: ghas-auto-tagger-${{ github.ref }}

.github/workflows/pulumi-preview.yml

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -3,37 +3,37 @@ on:
33
inputs:
44
aws-role:
55
type: string
6-
default: ""
6+
default: ''
77
aws-region:
88
type: string
99
default: eu-west-1
1010
aws-secrets-mapping:
1111
type: string
12-
default: ""
12+
default: ''
1313
disable-sudo:
1414
type: boolean
1515
default: true
1616
egress-policy-allowlist:
1717
type: string
18-
default: ""
18+
default: ''
1919
poetry-version:
2020
type: string
21-
default: "latest"
21+
default: 'latest'
2222
python-version:
2323
type: string
24-
default: "3.13"
24+
default: '3.13'
2525
runs-on:
2626
type: string
27-
default: "ubuntu-latest"
27+
default: 'ubuntu-latest'
2828
stack-name:
2929
type: string
30-
default: ""
30+
default: ''
3131
working-directory:
3232
type: string
33-
default: "."
33+
default: '.'
3434

3535
concurrency:
36-
group: ghas-${{ github.repository }}-pulumi-preview-${{ github.ref }}
36+
group: ghas-${{ github.repository }}-pulumi-preview-${{ inputs.stack-name }}-${{ github.ref }}
3737
cancel-in-progress: true
3838

3939
jobs:
@@ -112,7 +112,7 @@ jobs:
112112
with:
113113
path: ${{ env.PULUMI_HOME }}/plugins
114114
key: python-${{ inputs.python-version }}-venv-${{ hashFiles(format('{0}/poetry.lock', inputs.working-directory), format('{0}/uv.lock', inputs.working-directory)) }}
115-
- uses: aws-actions/configure-aws-credentials@a03048d87541d1d9fcf2ecf528a4a65ba9bd7838 # v5.0.0
115+
- uses: aws-actions/configure-aws-credentials@00943011d9042930efac3dcd3a170e4273319bc8 # v5.1.0
116116
if: ${{ inputs.aws-role != '' }}
117117
with:
118118
role-to-assume: ${{ inputs.aws-role }}
@@ -124,6 +124,7 @@ jobs:
124124
secret-ids: >
125125
${{ inputs.aws-secrets-mapping }}
126126
- uses: pulumi/actions@d7ceb0215da5a14ec84f50b703365ddf0194a9c8 # v6.6.0
127+
name: Pulumi Preview
127128
with:
128129
command: preview
129130
stack-name: ${{ inputs.stack-name }}

0 commit comments

Comments
 (0)