Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 7 additions & 4 deletions .github/actions/create-release-tag/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,11 +62,14 @@ runs:

- name: Create and push tag
shell: bash
env:
TAG: ${{ steps.next_tag.outputs.tag }}
run: |
tag="${{ steps.next_tag.outputs.tag }}"
git tag -a "${tag}" -m "Release ${tag}"
git push origin "${tag}"
git tag -a "${TAG}" -m "Release ${TAG}"
git push origin "${TAG}"

- name: Print created tag
shell: bash
run: echo "Created tag ${{ steps.next_tag.outputs.tag }}"
env:
TAG: ${{ steps.next_tag.outputs.tag }}
run: echo "Created tag ${TAG}"
37 changes: 37 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,16 @@
version: 2

# The 7-day cooldown skips freshly published (possibly compromised) releases;
# security updates are exempt.
updates:
- package-ecosystem: "gomod"
directory: "/"
schedule:
interval: "daily"
time: "09:00"
timezone: "Etc/UTC"
cooldown:
default-days: 7
open-pull-requests-limit: 10
labels:
- "semver: patch"
Expand All @@ -24,6 +29,8 @@ updates:
interval: "daily"
time: "09:00"
timezone: "Etc/UTC"
cooldown:
default-days: 7
open-pull-requests-limit: 10
labels:
- "semver: patch"
Expand All @@ -42,6 +49,8 @@ updates:
interval: "daily"
time: "10:00"
timezone: "Etc/UTC"
cooldown:
default-days: 7
open-pull-requests-limit: 10
labels:
- "semver: patch"
Expand All @@ -53,3 +62,31 @@ updates:
update-types:
- "minor"
- "patch"

# Bumps the hook revs, including the zizmor version zizmor.yml runs in CI.
- package-ecosystem: "pre-commit"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
time: "10:00"
timezone: "Etc/UTC"
cooldown:
default-days: 7
labels:
- "semver: patch"
- "docs: skip"

# Bumps pre-commit itself, which zizmor.yml installs from this file.
- package-ecosystem: "pip"
directory: "/.github/tools"
schedule:
interval: "weekly"
day: "monday"
time: "10:00"
timezone: "Etc/UTC"
cooldown:
default-days: 7
labels:
- "semver: patch"
- "docs: skip"
1 change: 1 addition & 0 deletions .github/tools/requirements.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
pre-commit==4.6.2
24 changes: 14 additions & 10 deletions .github/workflows/automated-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,9 @@ on:
- cron: "0 10 * * 4" # Every Thursday at 10 AM UTC
workflow_dispatch:

# Only the `ci` job needs write scopes, granted there for ci.yml's jobs.
permissions:
contents: write
pull-requests: write
checks: write
security-events: write
contents: read

concurrency:
group: create-release-tag
Expand All @@ -28,9 +26,9 @@ jobs:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: main
fetch-depth: 0
token: ${{ secrets.PRO_ACCESS_TOKEN }}

- name: Fetch tags
run: git fetch --tags --force
Expand Down Expand Up @@ -66,9 +64,9 @@ jobs:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: main
fetch-depth: 0
token: ${{ secrets.PRO_ACCESS_TOKEN }}

- name: Fetch tags
run: git fetch --tags --force
Expand Down Expand Up @@ -115,16 +113,22 @@ jobs:
name: CI
needs: check-changes
if: needs.check-changes.outputs.has_changes == 'true'
uses: ./.github/workflows/ci.yml
secrets: inherit
uses: $/.github/workflows/ci.yml
# Must cover every scope ci.yml's jobs declare, even `release`, which is
# skipped here but still validated.
permissions:
contents: write
security-events: write # govulncheck SARIF upload
secrets:
LOCALSTACK_AUTH_TOKEN: ${{ secrets.LOCALSTACK_AUTH_TOKEN }}

create-tag:
name: Create release tag
needs: [check-changes, determine-bump, ci]
if: needs.check-changes.outputs.has_changes == 'true'
runs-on: ubuntu-latest
steps:
- name: Checkout code
- name: Checkout code # zizmor: ignore[artipacked] the tag push needs it; this job uploads no artifacts
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: main
Expand All @@ -135,6 +139,6 @@ jobs:
run: git fetch --tags --force

- name: Create release tag
uses: ./.github/actions/create-release-tag
uses: $/.github/actions/create-release-tag
with:
bump: ${{ needs.determine-bump.outputs.bump }}
3 changes: 3 additions & 0 deletions .github/workflows/check-release-label.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@ on:
pull_request:
types: [opened, labeled, unlabeled, synchronize, reopened]

# The check reads labels off the event payload, so it needs no API access.
permissions: {}

jobs:
check-label:
name: Require release label
Expand Down
50 changes: 37 additions & 13 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,11 +9,16 @@ on:
pull_request:
workflow_dispatch:
workflow_call:

# Replaces `secrets: inherit`. Only governs workflow_call runs, which skip
# `release`; a direct tag push still sees every repo secret.
secrets:
LOCALSTACK_AUTH_TOKEN:
required: false

# A scope added to any job below must also be granted by automated-release.yml's
# `ci` job, or the weekly release fails at startup with no job logs.
permissions:
contents: read
pull-requests: write
checks: write

# Cancel superseded runs on the same PR. Non-PR runs (push/tag/release) each
# get a unique group via run_id, so cancel-in-progress can never touch them —
Expand All @@ -30,8 +35,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Go
- name: Set up Go # zizmor: ignore[cache-poisoning] non-publishing job
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
Expand All @@ -54,6 +61,8 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

# SARIF report for the Security tab; never fails the job (gate steps
# below own pass/fail). repo-checkout: false everywhere: the action's
Expand Down Expand Up @@ -114,8 +123,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Go
- name: Set up Go # zizmor: ignore[cache-poisoning] non-publishing job
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
Expand Down Expand Up @@ -163,6 +174,8 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Download generated cask
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7.0.0
Expand All @@ -180,8 +193,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Go
- name: Set up Go # zizmor: ignore[cache-poisoning] non-publishing job
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
Expand Down Expand Up @@ -236,8 +251,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Go
- name: Set up Go # zizmor: ignore[cache-poisoning] non-publishing job
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
Expand Down Expand Up @@ -270,7 +287,7 @@ jobs:
# (cdk_e2e_test.go) run on the Docker-capable Linux shards. They skip
# automatically wherever cdk is absent (macOS/Windows). lstk requires
# CDK >= 2.177.0; the latest release satisfies that.
- name: Install AWS CDK
- name: Install AWS CDK # zizmor: ignore[adhoc-packages] unpinned on purpose, see above
if: matrix.os == 'ubuntu-latest'
run: npm install -g aws-cdk

Expand Down Expand Up @@ -323,9 +340,11 @@ jobs:
timeout-minutes: 5
steps:
- name: Verify integration matrix succeeded
env:
RESULT: ${{ needs.test-integration.result }}
run: |
if [ "${{ needs.test-integration.result }}" != "success" ]; then
echo "test-integration matrix result: ${{ needs.test-integration.result }}"
if [ "${RESULT}" != "success" ]; then
echo "test-integration matrix result: ${RESULT}"
exit 1
fi

Expand All @@ -335,8 +354,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Set up Node.js
- name: Set up Node.js # zizmor: ignore[cache-poisoning] non-publishing job
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "20"
Expand Down Expand Up @@ -364,13 +385,15 @@ jobs:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0

# No cache in the publishing job, so a poisoned entry can't reach a release.
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache-dependency-path: go.sum
cache: false

- name: Validate version tag
run: |
Expand Down Expand Up @@ -434,6 +457,7 @@ jobs:
with:
node-version: "20"
registry-url: "https://registry.npmjs.org"
package-manager-cache: false

# Build the platform packages and main wrapper package from the
# GoReleaser output. This is the same tool the previous
Expand Down Expand Up @@ -464,7 +488,7 @@ jobs:
- name: Add bundled extensions to the npm platform packages
run: scripts/bundled-extensions/add-bundled-to-npm.sh dist/npm bundled

- name: Publish to NPM
- name: Publish to NPM # zizmor: ignore[use-trusted-publishing] needs npm-side setup first
run: |
for dir in dist/npm/lstk-*/ dist/npm/lstk/; do
npm publish "$dir" --access public
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/create-release-tag.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,9 @@ on:
- patch
- minor

# The tag push authenticates with PRO_ACCESS_TOKEN, not GITHUB_TOKEN.
permissions:
contents: write
contents: read

concurrency:
group: create-release-tag
Expand All @@ -29,7 +30,7 @@ jobs:
if: github.repository == 'localstack/lstk'
runs-on: ubuntu-latest
steps:
- name: Checkout code
- name: Checkout code # zizmor: ignore[artipacked] the tag push needs it; this job uploads no artifacts
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.release_ref }}
Expand All @@ -39,7 +40,8 @@ jobs:
- name: Fetch tags
run: git fetch --tags --force

# $/ runs the action from this workflow's commit, not the checked-out release_ref.
- name: Create release tag
uses: ./.github/actions/create-release-tag
uses: $/.github/actions/create-release-tag
with:
bump: ${{ inputs.bump }}
7 changes: 7 additions & 0 deletions .github/workflows/enforce-labels.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,15 @@
name: Enforce Labels
on:
# Runs the base branch's copy, so a PR can't weaken its own label gate.
# Never check out or run PR code here.
# zizmor: ignore[dangerous-triggers] reads labels only, never checks out PR code
pull_request_target:
types: [labeled, unlabeled, opened, synchronize]

permissions:
# Enough while add_comment stays at its default of false.
pull-requests: read

jobs:
docs:
runs-on: ubuntu-latest
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/linear-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ jobs:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0

- name: Create Linear release
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/sync-labels.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ on:
- cron: "0 0 * * *"
workflow_dispatch:

# The called workflow uses the github-token secret, never GITHUB_TOKEN.
permissions: {}

jobs:
sync-labels:
uses: localstack/meta/.github/workflows/sync-labels.yml@83b4ff2ee4169d58eeb35bfa6dcddf9f35388212 # main @ 2026-04-22
Expand Down
Loading
Loading