-
Notifications
You must be signed in to change notification settings - Fork 1
chore(CI): Try actionlint update #264
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -22,10 +22,10 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v7 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Pin all updated action references in both workflows to full commit SHAs. Both files still use version tags for the changed action references. Replace each tag with the action’s verified full commit SHA.
As per path instructions, “Pin action versions to full SHA, not tags (supply chain safety).” 🧰 Tools🪛 zizmor (1.30.1)[warning] 24-25: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [warning] 1-155: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 25-25: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 📍 Affects 2 files
🤖 Prompt for AI AgentsSources: Path instructions, Linters/SAST tools |
||
|
|
||
| - name: Set up Go | ||
| uses: actions/setup-go@v5 | ||
| uses: actions/setup-go@v7 | ||
| with: | ||
| go-version-file: go.mod | ||
| cache-dependency-path: | | ||
|
|
@@ -101,7 +101,7 @@ jobs: | |
| - name: Upload test artifacts | ||
| if: always() | ||
| id: upload_artifacts | ||
| uses: actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@v7 | ||
| with: | ||
| name: e2e-test-results | ||
| path: | | ||
|
|
@@ -121,7 +121,7 @@ jobs: | |
|
|
||
| - name: Create or update comment - Success | ||
| if: success() | ||
| uses: peter-evans/create-or-update-comment@v4 | ||
| uses: peter-evans/create-or-update-comment@v5 | ||
| with: | ||
| comment-id: ${{ steps.find_comment.outputs.comment-id }} | ||
| issue-number: ${{ github.event.pull_request.number }} | ||
|
|
@@ -140,7 +140,7 @@ jobs: | |
|
|
||
| - name: Create or update comment - Failure | ||
| if: failure() | ||
| uses: peter-evans/create-or-update-comment@v4 | ||
| uses: peter-evans/create-or-update-comment@v5 | ||
| with: | ||
| comment-id: ${{ steps.find_comment.outputs.comment-id }} | ||
| issue-number: ${{ github.event.pull_request.number }} | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -18,10 +18,10 @@ jobs: | |
|
|
||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v7 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Pin the changed actions to full commit SHAs. These workflows use version tags for the changed action references. Pin each reference to a full SHA. As per path instructions: “Pin action versions to full SHA, not tags (supply chain safety).”
🧰 Tools🪛 zizmor (1.30.1)[warning] 20-21: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [warning] 1-135: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 14-135: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 21-21: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 📍 Affects 4 files
🤖 Prompt for AI AgentsSource: Path instructions |
||
|
|
||
| - name: Set up Go | ||
| uses: actions/setup-go@v5 | ||
| uses: actions/setup-go@v7 | ||
| with: | ||
| go-version-file: go.mod | ||
|
|
||
|
|
@@ -34,7 +34,7 @@ jobs: | |
| cluster_name: stackrox-mcp-smoke | ||
|
|
||
| - name: Checkout StackRox repository | ||
| uses: actions/checkout@v4 | ||
| uses: actions/checkout@v7 | ||
| with: | ||
| repository: stackrox/stackrox | ||
| path: stackrox-repo | ||
|
|
@@ -94,7 +94,7 @@ jobs: | |
|
|
||
| - name: Upload JUnit test results | ||
| if: always() | ||
| uses: actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@v7 | ||
| with: | ||
| name: junit-smoke-results | ||
| path: junit-smoke.xml | ||
|
|
@@ -127,7 +127,7 @@ jobs: | |
|
|
||
| - name: Upload logs | ||
| if: always() | ||
| uses: actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@v7 | ||
| with: | ||
| name: smoke-test-logs | ||
| path: logs/ | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3,9 +3,9 @@ module github.com/stackrox/stackrox-mcp/e2e-tests | |
| go 1.26.3 | ||
|
|
||
| require ( | ||
| actionlint.kjanat.dev v1.17.0 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -euo pipefail
rg -n -C 5 'setup-go|go-version|make actionlint' .github/workflows/style.ymlRepository: stackrox/stackrox-mcp Length of output: 561 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- .github/workflows/style.yml ---'
cat -n .github/workflows/style.yml
printf '%s\n' '--- actionlint references ---'
rg -n -C 8 'actionlint|e2e-tests/tools|GOTOOLCHAIN|go-version' Makefile e2e-tests/tools/go.mod .github/workflows
printf '%s\n' '--- changed dependency declaration ---'
cat -n e2e-tests/tools/go.mod | sed -n '1,35p'Repository: stackrox/stackrox-mcp Length of output: 11348 🌐 Web query:
💡 Result: Pin the Go version for the Style job.
Suggested fix - name: Set up Go
uses: actions/setup-go@v7
+ with:
+ go-version-file: e2e-tests/tools/go.mod🤖 Prompt for AI AgentsSource: Pipeline failures |
||
| github.com/fullstorydev/grpcurl v1.9.4 | ||
| github.com/mcpchecker/mcpchecker v0.0.19 | ||
| github.com/rhysd/actionlint v1.7.12 | ||
| ) | ||
|
|
||
| require ( | ||
|
|
@@ -34,7 +34,7 @@ require ( | |
| github.com/bahlo/generic-list-go v0.2.0 // indirect | ||
| github.com/blang/semver v3.5.1+incompatible // indirect | ||
| github.com/bmatcuk/doublestar/v4 v4.10.0 // indirect | ||
| github.com/buger/jsonparser v1.1.1 // indirect | ||
| github.com/buger/jsonparser v1.1.2 // indirect | ||
| github.com/cenkalti/backoff/v5 v5.0.3 // indirect | ||
| github.com/cespare/xxhash/v2 v2.3.0 // indirect | ||
| github.com/charmbracelet/anthropic-sdk-go v0.0.0-20260223140439-63879b0b8dab // indirect | ||
|
|
@@ -94,21 +94,21 @@ require ( | |
| github.com/in-toto/attestation v1.1.2 // indirect | ||
| github.com/in-toto/in-toto-golang v0.9.0 // indirect | ||
| github.com/inconshreveable/mousetrap v1.1.0 // indirect | ||
| github.com/invopop/jsonschema v0.13.0 // indirect | ||
| github.com/invopop/jsonschema v0.14.0 // indirect | ||
| github.com/jhump/protoreflect v1.18.1 // indirect | ||
| github.com/jhump/protoreflect/v2 v2.0.0-beta.1 // indirect | ||
| github.com/kaptinlin/go-i18n v0.4.8 // indirect | ||
| github.com/kaptinlin/jsonpointer v0.4.23 // indirect | ||
| github.com/kaptinlin/jsonschema v0.7.14 // indirect | ||
| github.com/kaptinlin/messageformat-go v0.6.4 // indirect | ||
| github.com/mailru/easyjson v0.9.1 // indirect | ||
| github.com/mattn/go-colorable v0.1.14 // indirect | ||
| github.com/mattn/go-isatty v0.0.20 // indirect | ||
| github.com/mattn/go-runewidth v0.0.21 // indirect | ||
| github.com/mattn/go-shellwords v1.0.12 // indirect | ||
| github.com/mattn/go-colorable v0.1.15 // indirect | ||
| github.com/mattn/go-isatty v0.0.24 // indirect | ||
| github.com/mattn/go-runewidth v0.0.28 // indirect | ||
| github.com/mattn/go-shellwords v1.0.14 // indirect | ||
| github.com/modelcontextprotocol/go-sdk v1.6.1 // indirect | ||
| github.com/oklog/ulid v1.3.1 // indirect | ||
| github.com/opencontainers/go-digest v1.0.0 // indirect | ||
| github.com/pb33f/ordered-map/v2 v2.3.1 // indirect | ||
| github.com/petermattis/goid v0.0.0-20260113132338-7c7de50cc741 // indirect | ||
| github.com/pkg/errors v0.9.1 // indirect | ||
| github.com/pkoukk/tiktoken-go v0.1.8 // indirect | ||
|
|
@@ -134,7 +134,6 @@ require ( | |
| github.com/tidwall/sjson v1.2.5 // indirect | ||
| github.com/transparency-dev/formats v0.0.0-20260119090622-e70c80e9488a // indirect | ||
| github.com/transparency-dev/merkle v0.0.2 // indirect | ||
| github.com/wk8/go-ordered-map/v2 v2.1.8 // indirect | ||
| github.com/yosida95/uritemplate/v3 v3.0.2 // indirect | ||
| go.mongodb.org/mongo-driver v1.17.6 // indirect | ||
| go.opentelemetry.io/auto/sdk v1.2.1 // indirect | ||
|
|
@@ -145,7 +144,7 @@ require ( | |
| go.opentelemetry.io/otel/trace v1.44.0 // indirect | ||
| go.yaml.in/yaml/v2 v2.4.4 // indirect | ||
| go.yaml.in/yaml/v3 v3.0.4 // indirect | ||
| go.yaml.in/yaml/v4 v4.0.0-rc.3 // indirect | ||
| go.yaml.in/yaml/v4 v4.0.0-rc.6 // indirect | ||
| golang.org/x/crypto v0.55.0 // indirect | ||
| golang.org/x/exp/event v0.0.0-20260112195511-716be5621a96 // indirect | ||
| golang.org/x/exp/jsonrpc2 v0.0.0-20260112195511-716be5621a96 // indirect | ||
|
|
@@ -164,6 +163,5 @@ require ( | |
| google.golang.org/genproto/googleapis/rpc v0.0.0-20260825221802-da73d73af1c5 // indirect | ||
| google.golang.org/grpc v1.83.2 // indirect | ||
| google.golang.org/protobuf v1.36.12 // indirect | ||
| gopkg.in/yaml.v3 v3.0.1 // indirect | ||
| sigs.k8s.io/yaml v1.6.0 // indirect | ||
| ) | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Pin all five action references to full commit SHAs.
These references use major-version tags. A moved tag can change the action code that runs in this job, which receives Quay credentials. Replace each tag with a verified full commit SHA and keep the release version in a comment. GitHub documents that full commit SHAs are immutable and that tags can be moved or deleted. (docs.github.com)
As per path instructions, “Pin action versions to full SHA, not tags (supply chain safety).”
Also applies to: 32-32, 35-35, 43-43, 57-57
🧰 Tools
🪛 zizmor (1.30.1)
[warning] 28-29: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 1-83: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[error] 29-29: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Source: Path instructions