diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 4f64f78..30551fa 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -13,7 +13,7 @@ permissions: jobs: autofix: if: github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork - uses: Sea-Haven-Industries/.github/.github/workflows/ci-autofix.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-autofix.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 permissions: contents: write secrets: inherit @@ -24,7 +24,7 @@ jobs: lint: needs: autofix if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true') - uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: python-version: "3.12" @@ -59,7 +59,7 @@ jobs: terraform: needs: autofix if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true') - uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 with: terraform-version: "1.16.0" diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 7b8fb6f..bf5ba1b 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -7,4 +7,4 @@ permissions: jobs: review: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 diff --git a/.github/workflows/deploy-api.yaml b/.github/workflows/deploy-api.yaml index aa8534f..55a093a 100644 --- a/.github/workflows/deploy-api.yaml +++ b/.github/workflows/deploy-api.yaml @@ -43,7 +43,7 @@ jobs: deploy-dev: name: Deploy API to dev if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && inputs.environment == 'dev') - uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 permissions: contents: read id-token: write @@ -57,7 +57,7 @@ jobs: deploy-prod: name: Deploy API to prod if: github.event_name == 'release' || (github.event_name == 'workflow_dispatch' && inputs.environment == 'prod') - uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 permissions: contents: read id-token: write diff --git a/.github/workflows/labeler.yml b/.github/workflows/labeler.yml index 0b8a6cd..920bb16 100644 --- a/.github/workflows/labeler.yml +++ b/.github/workflows/labeler.yml @@ -10,4 +10,4 @@ permissions: jobs: label: - uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 + uses: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21 diff --git a/tests/infra/test_hcp_contract.py b/tests/infra/test_hcp_contract.py index 5b5c186..f2a0241 100644 --- a/tests/infra/test_hcp_contract.py +++ b/tests/infra/test_hcp_contract.py @@ -101,7 +101,7 @@ def test_ecs_task_boundary_uses_static_arns(): def test_deploy_api_workflow_exists(): deploy_api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text() - pin = "cd-hcp-fargate.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" + pin = "cd-hcp-fargate.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" assert deploy_api.count(pin) == 2 assert "ssm-prefix: /afterhours-shift-manager/deploy" in deploy_api assert "docker-platform: linux/arm64" in deploy_api @@ -119,9 +119,9 @@ def test_in_repo_hcptf_roles(): def test_ci_runs_pytest_and_terraform_validate(): assert "ci-python-sam" not in CI - assert "ci-python-app.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" in CI - assert "ci-terraform.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" in CI - assert "ci-autofix.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19" in CI + assert "ci-python-app.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" in CI + assert "ci-terraform.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" in CI + assert "ci-autofix.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21" in CI assert "name: ci-complete" in CI assert "pytest" in CI assert "terraform fmt -check" not in CI diff --git a/tests/requirements.txt b/tests/requirements.txt index 8c9815f..7c635a4 100644 --- a/tests/requirements.txt +++ b/tests/requirements.txt @@ -5,6 +5,6 @@ moto[dynamodb,ses,secretsmanager]>=5.2.2 responses>=0.26.2 freezegun>=1.5.5 sentry-sdk==2.68.1 -PyJWT[crypto]==2.14.0 +PyJWT[crypto]==2.15.0 flask==3.1.3