From 19d013b18495c3df2592d3837eadbc3a70dd42d6 Mon Sep 17 00:00:00 2001 From: paketo-bot Date: Wed, 23 Sep 2026 13:34:06 +0000 Subject: [PATCH] Updating github-config --- .github/dependabot.yml | 4 ++ .github/workflows/approve-bot-pr.yml | 8 ++- .github/workflows/codeql-analysis.yml | 16 ++++-- .github/workflows/compile-dependency.yml | 13 +++-- .github/workflows/create-draft-release.yml | 26 +++++---- .github/workflows/label-pr.yml | 13 +++-- .github/workflows/lint-yaml.yml | 11 +++- .github/workflows/lint.yml | 10 +++- .github/workflows/push-buildpackage.yml | 14 +++-- .github/workflows/synchronize-labels.yml | 16 ++++-- .github/workflows/test-pull-request.yml | 24 ++++---- .../update-dependencies-from-metadata.yml | 55 +++++++++++-------- .github/workflows/update-github-config.yml | 10 ++-- .github/workflows/update-go-mod-version.yml | 10 ++-- 14 files changed, 143 insertions(+), 87 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 56cb6d2e..d1ac78eb 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -16,6 +16,8 @@ updates: update-types: - "minor" - "patch" + cooldown: + default-days: 7 - package-ecosystem: gomod directory: "/dependency/retrieval" schedule: @@ -31,3 +33,5 @@ updates: update-types: - "minor" - "patch" + cooldown: + default-days: 7 diff --git a/.github/workflows/approve-bot-pr.yml b/.github/workflows/approve-bot-pr.yml index 0018b510..88c31fe3 100644 --- a/.github/workflows/approve-bot-pr.yml +++ b/.github/workflows/approve-bot-pr.yml @@ -6,8 +6,12 @@ on: types: - completed +concurrency: + group: approve-bot-pr-${{ github.event.workflow_run.pull_requests[0].number }} + cancel-in-progress: false + permissions: - actions: read + actions: read # download the event artifact from the triggering workflow run contents: read jobs: @@ -56,7 +60,7 @@ jobs: - name: Checkout if: steps.human-commits.outputs.human_commits == 'false' && steps.unverified-commits.outputs.unverified_commits == 'false' - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index 154e3962..373a05b2 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -6,14 +6,20 @@ on: schedule: - cron: '34 5 * * *' # daily at 5:34am UTC +concurrency: + group: codeql-analysis-${{ github.ref }} + cancel-in-progress: true + permissions: contents: read - security-events: write jobs: analyze: name: Analyze runs-on: ubuntu-24.04 + permissions: + contents: read + security-events: write # upload CodeQL results to GitHub code scanning strategy: fail-fast: false @@ -23,17 +29,17 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4 + uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 with: languages: ${{ matrix.language }} - name: Autobuild - uses: github/codeql-action/autobuild@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4 + uses: github/codeql-action/autobuild@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4 + uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 diff --git a/.github/workflows/compile-dependency.yml b/.github/workflows/compile-dependency.yml index c27324f9..015cca75 100644 --- a/.github/workflows/compile-dependency.yml +++ b/.github/workflows/compile-dependency.yml @@ -36,17 +36,20 @@ on: type: string permissions: - actions: write contents: read jobs: compile: + name: Compile dependency # Speed up compilation by using runners that match os and arch when they are set, otherwise fall back to emulation. runs-on: ${{ (inputs.os == 'linux' && inputs.arch == 'arm64') && 'ubuntu-24.04-arm' || 'ubuntu-24.04' }} + permissions: + actions: write # upload the compiled dependency artifact + contents: read steps: - name: Check out code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -58,10 +61,10 @@ jobs: echo '{"experimental": "enabled"}' | sudo tee ~/.docker/config.json - name: Set up QEMU - uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4 + uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4 + uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 - name: Setup before compilation id: compile-setup @@ -112,7 +115,7 @@ jobs: arch="${ARCH}" - name: Upload compiled artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: ${{ inputs.shouldCompile == true || inputs.shouldCompile == 'true' }} with: name: '${{ inputs.uploadArtifactName }}' diff --git a/.github/workflows/create-draft-release.yml b/.github/workflows/create-draft-release.yml index 011af736..94b12aea 100644 --- a/.github/workflows/create-draft-release.yml +++ b/.github/workflows/create-draft-release.yml @@ -12,7 +12,9 @@ on: description: 'Version of the release to cut (e.g. 1.2.3)' required: false -concurrency: release +concurrency: + group: release + cancel-in-progress: false permissions: contents: read @@ -25,11 +27,11 @@ jobs: builders: ${{ steps.builders.outputs.builders }} steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod - name: Run Unit Tests @@ -37,8 +39,8 @@ jobs: - name: Get builders from integration.json id: builders run: | - source "${{ github.workspace }}/scripts/.util/builders.sh" - builders="$(util::builders::list "${{ github.workspace }}/integration.json")" + source "${GITHUB_WORKSPACE}/scripts/.util/builders.sh" + builders="$(util::builders::list "${GITHUB_WORKSPACE}/integration.json")" printf "Output: %s\n" "${builders}" printf "builders=%s\n" "${builders}" >> "$GITHUB_OUTPUT" @@ -48,18 +50,18 @@ jobs: needs: unit permissions: contents: read - packages: read + packages: read # pull builder images for integration tests strategy: matrix: builder: ${{ fromJSON(needs.unit.outputs.builders) }} fail-fast: false # don't cancel all test jobs when one fails steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod - name: Free Disk Space @@ -92,22 +94,22 @@ jobs: runs-on: ubuntu-24.04 needs: integration permissions: - contents: write + contents: write # create and update the draft release services: registry: - image: registry:3 + image: registry:3@sha256:fd374bae807c225661adfe2c0c1f9970a0b8fab1761fd7dfb91e0fd9a8748f9b ports: - 5000:5000 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false fetch-tags: true - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod diff --git a/.github/workflows/label-pr.yml b/.github/workflows/label-pr.yml index 2d088a1b..684baa71 100644 --- a/.github/workflows/label-pr.yml +++ b/.github/workflows/label-pr.yml @@ -10,18 +10,23 @@ on: - labeled - unlabeled -concurrency: pr_labels_${{ github.event.number }} +concurrency: + group: pr_labels_${{ github.event.number }} + cancel-in-progress: false + +permissions: + contents: read jobs: autolabel: name: Ensure Minimal Semver Labels runs-on: ubuntu-24.04 permissions: - issues: read - pull-requests: read + issues: read # read the issue's current labels + pull-requests: read # read the pull request's metadata steps: - name: Check Minimal Semver Labels - uses: mheap/github-action-required-labels@23e10fde7e062233401931a0eece796cd9bf3177 # v5 + uses: mheap/github-action-required-labels@23e10fde7e062233401931a0eece796cd9bf3177 # v5.6.0 with: count: 1 labels: semver:major, semver:minor, semver:patch diff --git a/.github/workflows/lint-yaml.yml b/.github/workflows/lint-yaml.yml index 78182ded..c9d20c80 100644 --- a/.github/workflows/lint-yaml.yml +++ b/.github/workflows/lint-yaml.yml @@ -6,26 +6,31 @@ on: - '.github/**.yml' - '.github/**.yaml' +concurrency: + group: lint-yaml-${{ github.ref }} + cancel-in-progress: true + permissions: contents: read jobs: lintYaml: + name: Lint YAML runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Checkout github-config - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false repository: paketo-buildpacks/github-config path: github-config - name: Set up Python - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 + uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: 3.14 diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 1540851d..e7058326 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -5,6 +5,10 @@ on: branches: - main +concurrency: + group: lint-${{ github.ref }} + cancel-in-progress: true + permissions: contents: read @@ -14,17 +18,17 @@ jobs: runs-on: ubuntu-24.04 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod - name: golangci-lint - uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9 + uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9.3.0 with: version: latest args: --timeout 3m0s diff --git a/.github/workflows/push-buildpackage.yml b/.github/workflows/push-buildpackage.yml index 395bffc7..e425de32 100644 --- a/.github/workflows/push-buildpackage.yml +++ b/.github/workflows/push-buildpackage.yml @@ -5,6 +5,10 @@ on: types: - published +concurrency: + group: push-buildpackage + cancel-in-progress: false + env: REGISTRIES_FILENAME: "registries.json" @@ -26,7 +30,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -67,7 +71,7 @@ jobs: - name: Parse Configs id: parse_configs run: | - registries_filename="${{ env.REGISTRIES_FILENAME }}" + registries_filename="${REGISTRIES_FILENAME}" push_to_dockerhub=true push_to_gcr=false @@ -105,14 +109,14 @@ jobs: fi - name: Docker login docker.io - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: username: ${{ env.DOCKERHUB_USERNAME }} password: ${{ env.DOCKERHUB_PASSWORD }} registry: ${{ env.DOCKERHUB_REGISTRY }} - name: Docker login gcr.io - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 if: ${{ steps.parse_configs.outputs.push_to_gcr == 'true' }} with: username: ${{ env.GCR_USERNAME }} @@ -172,7 +176,7 @@ jobs: sudo skopeo copy "docker://${DOCKERHUB_REGISTRY}/${PUSH_IMAGE}" "docker://${GCR_REGISTRY}/${REPOSITORY}:latest" --multi-arch all - name: Register with CNB Registry - uses: docker://ghcr.io/buildpacks/actions/registry/request-add-entry@sha256:de7c15d1b8606c3189f0b5699bfdfe20afe5f6a315155932e801f334b0dae8f4 + uses: docker://ghcr.io/buildpacks/actions/registry/request-add-entry@sha256:de7c15d1b8606c3189f0b5699bfdfe20afe5f6a315155932e801f334b0dae8f4 # main with: id: ${{ github.repository }} version: ${{ steps.event.outputs.tag_full }} diff --git a/.github/workflows/synchronize-labels.yml b/.github/workflows/synchronize-labels.yml index 1bef3d90..e95f4f3c 100644 --- a/.github/workflows/synchronize-labels.yml +++ b/.github/workflows/synchronize-labels.yml @@ -1,23 +1,27 @@ name: Synchronize Labels -"on": +on: push: branches: - main paths: - .github/labels.yml workflow_dispatch: {} +concurrency: + group: synchronize-labels + cancel-in-progress: false permissions: contents: read - issues: write jobs: synchronize: name: Synchronize Labels - runs-on: - - ubuntu-24.04 + runs-on: ubuntu-24.04 + permissions: + contents: read + issues: write # create, update, and delete labels steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - - uses: micnncim/action-label-syncer@3abd5ab72fda571e69fffd97bd4e0033dd5f495c # v1 + - uses: micnncim/action-label-syncer@3abd5ab72fda571e69fffd97bd4e0033dd5f495c # v1.3.0 env: GITHUB_TOKEN: ${{ github.token }} diff --git a/.github/workflows/test-pull-request.yml b/.github/workflows/test-pull-request.yml index f172b41f..8bba8969 100644 --- a/.github/workflows/test-pull-request.yml +++ b/.github/workflows/test-pull-request.yml @@ -21,12 +21,12 @@ jobs: builders: ${{ steps.builders.outputs.builders }} steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod @@ -38,9 +38,9 @@ jobs: - name: Get builders from integration.json id: builders run: | - source "${{ github.workspace }}/scripts/.util/builders.sh" + source "${GITHUB_WORKSPACE}/scripts/.util/builders.sh" - builders="$(util::builders::list "${{ github.workspace }}/integration.json")" + builders="$(util::builders::list "${GITHUB_WORKSPACE}/integration.json")" printf "Output: %s\n" "${builders}" printf "builders=%s\n" "${builders}" >> "$GITHUB_OUTPUT" @@ -50,14 +50,14 @@ jobs: needs: unit permissions: contents: read - packages: read + packages: read # pull builder images for integration tests strategy: matrix: builder: ${{ fromJSON(needs.unit.outputs.builders) }} fail-fast: false # don't cancel all test jobs when one fails steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -74,7 +74,7 @@ jobs: swap-storage: true - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: go-version-file: go.mod @@ -97,8 +97,10 @@ jobs: runs-on: ubuntu-24.04 needs: integration steps: - - run: | - result="${{ needs.integration.result }}" + - env: + RESULT: ${{ needs.integration.result }} + run: | + result="${RESULT}" if [[ $result == "success" ]]; then echo "Integration tests passed against all builders" exit 0 @@ -111,10 +113,10 @@ jobs: name: Upload Workflow Event Payload runs-on: ubuntu-24.04 permissions: - actions: write + actions: write # upload the workflow event payload artifact steps: - name: Upload Artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: event-payload path: ${{ github.event_path }} diff --git a/.github/workflows/update-dependencies-from-metadata.yml b/.github/workflows/update-dependencies-from-metadata.yml index b56a44a2..8ef52dfc 100644 --- a/.github/workflows/update-dependencies-from-metadata.yml +++ b/.github/workflows/update-dependencies-from-metadata.yml @@ -5,6 +5,10 @@ on: schedule: - cron: '57 13 * * *' # daily at 13:57 UTC +concurrency: + group: update-dependencies-from-metadata + cancel-in-progress: false + permissions: contents: read @@ -14,7 +18,7 @@ jobs: runs-on: ubuntu-latest permissions: contents: read - actions: write + actions: write # upload the generated metadata artifacts outputs: metadata-filepath: ${{ steps.retrieve.outputs.metadata-filepath }} metadata-json: ${{ steps.retrieve.outputs.metadata-json }} @@ -29,12 +33,12 @@ jobs: compilation-length: ${{ steps.retrieve.outputs.compilation-length }} steps: - name: Check out code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: # hashFiles returns empty string if file does not exist go-version-file: ${{ hashFiles('dependency/retrieval/go.mod') != '' && 'dependency/retrieval/go.mod' || 'go.mod' }} @@ -50,7 +54,7 @@ jobs: OUTPUT="/tmp/metadata.json" make retrieve \ - buildpackTomlPath="${{ github.workspace }}/buildpack.toml" \ + buildpackTomlPath="${GITHUB_WORKSPACE}/buildpack.toml" \ output="${OUTPUT}" id=$(jq -r .[0].id < "${OUTPUT}") @@ -73,13 +77,13 @@ jobs: echo "compilation-length=$complength" >> "$GITHUB_OUTPUT" - name: Upload `${{ steps.retrieve.outputs.metadata-filepath }}` - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: metadata.json path: ${{ steps.retrieve.outputs.metadata-filepath }} - name: Upload `${{ steps.retrieve.outputs.from-source-metadata-filepath }}` - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: from-source-metadata.json path: ${{ steps.retrieve.outputs.from-source-metadata-filepath }} @@ -95,7 +99,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Check out code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -132,7 +136,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Check out code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false @@ -179,7 +183,7 @@ jobs: - get-compile-and-test permissions: contents: read - actions: write + actions: write # upload the compiled dependency artifacts strategy: matrix: includes: ${{ fromJSON(needs.retrieve.outputs.compilation-json) }} @@ -208,7 +212,7 @@ jobs: - compile permissions: contents: read - actions: write + actions: write # upload the updated metadata artifacts strategy: matrix: includes: ${{ fromJSON(needs.retrieve.outputs.compilation-json) }} @@ -216,12 +220,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Check out code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Download artifact files - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: "${{ needs.retrieve.outputs.id }}-${{ matrix.includes.version }}-${{ matrix.includes.os != '' && matrix.includes.os || 'linux' }}-${{ matrix.includes.arch != '' && matrix.includes.arch || 'amd64' }}-${{ matrix.includes.target }}" @@ -236,7 +240,7 @@ jobs: echo "checksum-file=$(basename ./*.tgz.checksum)" >> "$GITHUB_OUTPUT" - name: Configure AWS Credentials - uses: aws-actions/configure-aws-credentials@cbe3b392738ccf3f987d68400dafcf4b0624a56c # v6 + uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0 with: aws-access-key-id: ${{ secrets.AWS_S3_DEPENDENCIES_ACCESS_KEY_ID }} aws-secret-access-key: ${{ secrets.AWS_S3_DEPENDENCIES_SECRET_ACCESS_KEY }} @@ -257,7 +261,7 @@ jobs: run: echo "checksum=$(cat "${CHECKSUM_FILE}")" >> "$GITHUB_OUTPUT" - name: Download metadata.json - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: metadata.json @@ -265,17 +269,22 @@ jobs: # Due to limitations with the upload action, we can no longer modify/upload the same metadata file - name: Write dependency-specific metadata to new file id: dependency-metadata + env: + TARGET: ${{ matrix.includes.target }} + VERSION: ${{ matrix.includes.version }} + OS: ${{ matrix.includes.os }} + ARCH: ${{ matrix.includes.arch }} run: | #!/usr/bin/env bash set -euo pipefail shopt -s inherit_errexit - metadata_file_name="${{ matrix.includes.target }}-${{ matrix.includes.version }}-${{ matrix.includes.os != '' && matrix.includes.os || 'linux' }}-${{ matrix.includes.arch != '' && matrix.includes.arch || 'amd64' }}-metadata-file.json" - if [[ -z "${{ matrix.includes.os }}" && -z "${{ matrix.includes.arch }}" ]]; then - cat metadata.json | jq -r ['.[] | select( .version == "${{ matrix.includes.version }}" and .target == "${{ matrix.includes.target }}")'] > $metadata_file_name + metadata_file_name="${TARGET}-${VERSION}-${OS:-linux}-${ARCH:-amd64}-metadata-file.json" + if [[ -z "${OS}" && -z "${ARCH}" ]]; then + cat metadata.json | jq -r --arg version "${VERSION}" --arg target "${TARGET}" '[.[] | select( .version == $version and .target == $target )]' > $metadata_file_name else echo "multi-arch buildpack with os and arch specified" - cat metadata.json | jq -r ['.[] | select( .version == "${{ matrix.includes.version }}" and .target == "${{ matrix.includes.target }}" and .os == "${{ matrix.includes.os }}" and .arch == "${{ matrix.includes.arch }}")'] > $metadata_file_name + cat metadata.json | jq -r --arg version "${VERSION}" --arg target "${TARGET}" --arg os "${OS}" --arg arch "${ARCH}" '[.[] | select( .version == $version and .target == $target and .os == $os and .arch == $arch )]' > $metadata_file_name fi echo "file=$(echo $metadata_file_name)" >> "$GITHUB_OUTPUT" @@ -292,7 +301,7 @@ jobs: arch: ${{ matrix.includes.arch }} - name: Upload modified metadata - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ steps.dependency-metadata.outputs.file }} path: ${{ steps.dependency-metadata.outputs.file }} @@ -306,7 +315,7 @@ jobs: - update-metadata permissions: contents: read - actions: read + actions: read # download the metadata artifacts # Update buildpack.toml only if ALL of the following conditions are met: # (1) Retrieval step has succeeded and has found at least 1 new version # (2) Testing step has succeeded OR been skipped @@ -317,7 +326,7 @@ jobs: steps: - name: Check out code # zizmor: ignore[artipacked] -- persistent credentials required for push-branch - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: token: ${{ secrets.PAKETO_BOT_GITHUB_TOKEN }} @@ -333,7 +342,7 @@ jobs: # Metadata file for the non-compiled dependencies, if there are any - name: Download metadata.json file - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: "${{ steps.make-outputdir.outputs.outputdir }}/metadata-files" pattern: "from-source-metadata.json" @@ -343,7 +352,7 @@ jobs: # Download each metadata file, and combine them into one - name: Download individual metadata-file.json file(s) if: ${{ needs.update-metadata.result == 'success' }} - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: "${{ steps.make-outputdir.outputs.outputdir }}/metadata-files" pattern: "*metadata-file.json" diff --git a/.github/workflows/update-github-config.yml b/.github/workflows/update-github-config.yml index 81c4fb9d..c7e5a0d6 100644 --- a/.github/workflows/update-github-config.yml +++ b/.github/workflows/update-github-config.yml @@ -5,7 +5,9 @@ on: - cron: '27 13 * * *' # daily at 13:27 UTC workflow_dispatch: {} -concurrency: github_config_update +concurrency: + group: github_config_update + cancel-in-progress: false permissions: contents: read @@ -18,12 +20,12 @@ jobs: - name: Checkout # zizmor: ignore[artipacked] -- persistent credentials required for push-branch - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: token: ${{ secrets.PAKETO_BOT_GITHUB_TOKEN }} - name: Checkout github-config - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false repository: paketo-buildpacks/github-config @@ -73,7 +75,7 @@ jobs: if: ${{ always() && needs.build.result == 'failure' }} permissions: contents: read - issues: write + issues: write # file a failure alert issue steps: - name: File Failure Alert Issue uses: paketo-buildpacks/github-config/actions/issue/file@main diff --git a/.github/workflows/update-go-mod-version.yml b/.github/workflows/update-go-mod-version.yml index 7bf22514..b1527fee 100644 --- a/.github/workflows/update-go-mod-version.yml +++ b/.github/workflows/update-go-mod-version.yml @@ -5,7 +5,9 @@ on: - cron: '48 4 * * MON' # every monday at 4:48 UTC workflow_dispatch: -concurrency: update-go +concurrency: + group: update-go + cancel-in-progress: false permissions: contents: read @@ -17,7 +19,7 @@ jobs: steps: - name: Check out code # zizmor: ignore[artipacked] -- persistent credentials required for push-branch - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: token: ${{ secrets.PAKETO_BOT_GITHUB_TOKEN }} - name: Checkout PR Branch @@ -26,7 +28,7 @@ jobs: branch: automation/go-mod-update/update-main - name: Setup Go id: setup-go - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7 + uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 # Fetching the latest stable Go version with: go-version: stable @@ -87,7 +89,7 @@ jobs: if: ${{ always() && needs.update-go.result == 'failure' }} permissions: contents: read - issues: write + issues: write # file a failure alert issue steps: - name: File Failure Alert Issue uses: paketo-buildpacks/github-config/actions/issue/file@main