From 8e90d41b6c9bf7cb88691cbfba34ec6b788da833 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 12 Jun 2026 11:42:55 -0400 Subject: [PATCH] Point release-notify invoke role trust at deploy.yaml (#113) The release job moved from release.yaml into deploy.yaml to clear CodeQL's workflow_run findings, but the OIDC invoke role's trust still pinned job_workflow_ref to release.yaml. That denied the AssumeRole at the release job's Configure-AWS step, so the v1.10.0 announcement never fired. Point the condition at deploy.yaml (the inline release job's top-level workflow) so the token's job_workflow_ref matches. --- template.yaml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/template.yaml b/template.yaml index fa0b5d4..c2bb6f6 100644 --- a/template.yaml +++ b/template.yaml @@ -300,9 +300,10 @@ Resources: token.actions.githubusercontent.com:aud: sts.amazonaws.com StringLike: token.actions.githubusercontent.com:sub: "repo:Sea-Haven-Industries/afterhours-shift-manager:ref:refs/heads/main" - # Defense-in-depth: only the release workflow may assume this role, - # not any workflow running on main. - token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/release.yaml@refs/heads/main" + # Defense-in-depth: only the Deploy workflow's release job may assume + # this role, not any workflow running on main. (The release job lives + # in deploy.yaml; this must match that workflow's path.) + token.actions.githubusercontent.com:job_workflow_ref: "Sea-Haven-Industries/afterhours-shift-manager/.github/workflows/deploy.yaml@refs/heads/main" Policies: - PolicyName: invoke-release-notifier PolicyDocument: