diff --git a/.github/workflows/cd-mobile-ios.yaml b/.github/workflows/cd-mobile-ios.yaml index 4a808f7..8f553b9 100644 --- a/.github/workflows/cd-mobile-ios.yaml +++ b/.github/workflows/cd-mobile-ios.yaml @@ -73,7 +73,7 @@ jobs: cache: npm cache-dependency-path: ${{ inputs.cache-dependency-path }} - - uses: ruby/setup-ruby@12fd324f1d0b43274fdc8130f6980590a667c455 # v1 + - uses: ruby/setup-ruby@89f90524b88a01fe6e0b732220432cc6142926af # v1 with: ruby-version: ${{ inputs.ruby-version }} bundler-cache: true diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml index 0d5f68d..967a9f3 100644 --- a/.github/workflows/cd-sam.yaml +++ b/.github/workflows/cd-sam.yaml @@ -46,7 +46,7 @@ jobs: with: python-version: ${{ inputs.python-version }} - - uses: aws-actions/setup-sam@v2 + - uses: aws-actions/setup-sam@v3 - uses: aws-actions/configure-aws-credentials@v6 with: diff --git a/.github/workflows/ci-python-sam.yaml b/.github/workflows/ci-python-sam.yaml index 9e9e8f0..bc9cb62 100644 --- a/.github/workflows/ci-python-sam.yaml +++ b/.github/workflows/ci-python-sam.yaml @@ -147,7 +147,7 @@ jobs: - name: Setup SAM CLI if: ${{ inputs.run-sam-validate }} - uses: aws-actions/setup-sam@v2 + uses: aws-actions/setup-sam@v3 - name: SAM validate if: ${{ inputs.run-sam-validate }} diff --git a/.github/workflows/ci-typescript-cdk.yaml b/.github/workflows/ci-typescript-cdk.yaml index 03a080d..00241bb 100644 --- a/.github/workflows/ci-typescript-cdk.yaml +++ b/.github/workflows/ci-typescript-cdk.yaml @@ -156,7 +156,7 @@ jobs: - name: Setup SAM CLI if: ${{ inputs.run-sam-validate }} - uses: aws-actions/setup-sam@v2 + uses: aws-actions/setup-sam@v3 - name: SAM validate if: ${{ inputs.run-sam-validate }} diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml new file mode 100644 index 0000000..5b31360 --- /dev/null +++ b/.github/workflows/ci.yaml @@ -0,0 +1,60 @@ +name: ci + +# Self-CI for this org `.github` repo. +# +# The org ruleset "main branch protection" requires the `ci / ci` status check on +# every repo. Consumer repos satisfy it via a short caller workflow that invokes +# the reusable workflows here. This repo only HOUSES those reusable workflows +# (all `workflow_call`-only), so nothing emitted `ci / ci` and every PR sat +# permanently "Expected — Waiting for status to be reported" and could not merge. +# +# This workflow produces that check by linting the workflow files with actionlint +# — genuinely useful CI for a repo whose whole product is GitHub Actions YAML. +# +# Naming is load-bearing: the ruleset matches the required status check against +# the JOB's check-run name, NOT "workflow / job". For a normal (non-reusable) job +# the check-run name IS the job name, so the job must be named literally "ci / ci" +# to emit that exact context. (A job named "ci" emits the context "ci" — which the +# PR UI cosmetically *displays* as "ci / ci" but does NOT satisfy the requirement.) +# This mirrors the org's aggregator-job convention. +# +# actionlint is pinned to a tagged release and installed by downloading the +# release tarball and verifying its SHA256 — not `curl | bash` — to keep the +# supply-chain surface auditable. Bump ACTIONLINT_VERSION + ACTIONLINT_SHA256 +# together (checksum from the release's *_checksums.txt). +# +# actionlint's shellcheck integration is disabled (`-shellcheck=`) for now: it +# reports 4 pre-existing findings in the deploy/CI run-steps (SC2044 find-in-for +# loops, SC2046/SC2086 quoting, one of which is intentional word-splitting in the +# SAM deploy step). Those deserve a separate, tested cleanup rather than being +# bundled into the gate that unblocks the repo. Re-enable shellcheck once fixed. + +on: + pull_request: + push: + branches: [main] + +permissions: + contents: read + +jobs: + ci: + name: ci / ci + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + + - name: Install actionlint + env: + ACTIONLINT_VERSION: 1.7.12 + ACTIONLINT_SHA256: 8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 + run: | + curl -fsSL -o actionlint.tar.gz \ + "https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz" + echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum -c - + tar -xzf actionlint.tar.gz actionlint + shell: bash + + - name: Lint workflows + run: ./actionlint -color -shellcheck= + shell: bash diff --git a/.github/workflows/compliance-audit.yaml b/.github/workflows/compliance-audit.yaml index 96c4409..39b7ea6 100644 --- a/.github/workflows/compliance-audit.yaml +++ b/.github/workflows/compliance-audit.yaml @@ -76,7 +76,7 @@ jobs: - name: Run compliance audit id: audit - uses: anthropics/claude-code-action@0f97b95b6536c26e5f6bd90faec370d41695beca # v1 + uses: anthropics/claude-code-action@4d7e1f0cd85743fdc93b1c8040ab54395da024e2 # v1 with: anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }} prompt: | diff --git a/.github/workflows/labeler.yaml b/.github/workflows/labeler.yaml new file mode 100644 index 0000000..6f3a8c0 --- /dev/null +++ b/.github/workflows/labeler.yaml @@ -0,0 +1,25 @@ +name: labeler + +# Thin caller that runs the org-wide reusable PR labeler (callable-labeler.yaml) +# on THIS repo's own pull requests. The .github repo is the single source of truth +# for the reusable workflows, but — like any consumer repo — it must invoke them +# via a caller to use them on itself; without this, the labeler never runs on +# .github's own PRs (the reusable is `workflow_call`-only). +# +# Permissions are load-bearing: callers MUST grant all three below. Reusable- +# workflow permissions can only be downgraded from the caller, so omitting one +# (e.g. issues:write) either fails to create labels or triggers a silent +# startup_failure. `pull_request` (NOT pull_request_target) is correct here — the +# org takes no fork PRs, so the lower-privilege event is sufficient. + +on: + pull_request: + +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + label: + uses: ./.github/workflows/callable-labeler.yaml