Skip to content

Latest commit

 

History

History
288 lines (247 loc) · 13.5 KB

File metadata and controls

288 lines (247 loc) · 13.5 KB

Changelog

[v8.2.0] - 2026-09-03

Added

  • setup-git-auth
    • New action. Configures authenticated git access to github.com for the whole job via http.https://github.com/.extraheader (the same mechanism actions/checkout uses), so tools that clone other repositories mid-job (mr.developer, git submodules, go get, pip install git+...) no longer clone anonymously. Sources declared with an SSH URL are rewritten to authenticated HTTPS through tokenless insteadOf entries
    • MODE input (default setup) — cleanup removes the credentials again. Composite actions cannot declare a post: step, so teardown is an explicit second call, typically with if: always()
    • GITHUB_TOKEN input — required when MODE is setup. Both the token and its base64 form are passed to ::add-mask::, since a composite-action input is auto-masked only when the caller passed an actual secret
  • plone-package-test-notify
    • New optional GITHUB_TOKEN input — when set, the action calls setup-git-auth right after the checkout and cleans up at the end, so mr.developer source checkouts are authenticated instead of anonymous. Fixes intermittent fatal: could not read Username for 'https://github.com': No such device or address buildout failures caused by GitHub answering anonymous clones with a 401, and allows private sources. Pass GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}; leaving it unset keeps the previous anonymous behaviour

[v8.1.0] - 2026-07-15

Added

  • helm-release-notify
    • Optional GPG provenance signing (see https://helm.sh/docs/topics/provenance/). When SIGNER_KEY is provided, the chart is packaged with helm package --sign and the resulting <chart>-<version>.tgz.prov is published to gh-pages next to the .tgz, so consumers can run helm install/pull --verify
    • New SIGNER_KEY input — GPG private key (base64 encoded) used to sign the chart. If empty, the chart is published unsigned (unchanged behavior)
    • New SIGNER_KEY_ID input — GPG key fingerprint/ID used to export the legacy signing keyring; required when SIGNER_KEY is set
    • New SIGNER_KEY_PASSPHRASE input — passphrase for the GPG signing key; required when SIGNER_KEY is set
    • Mattermost notification body now includes a Signed: line

Changed

  • helm-release-notify
    • Replaced the third-party tylerauerbeck/helm-gh-pages Docker action with an inline publish step (Helm installed from get.helm.sh; chart located, dependencies resolved, linted, packaged, and pushed to gh-pages in-action). The published index.yaml URL scheme and test/stable TARGET_DIR layout are preserved, so existing unsigned callers are unaffected

[v8.0.0] - 2026-04-29

Changed

  • trivy-scan-notify
    • Breaking: SEVERITY input renamed to SEVERITIES — update callers accordingly
    • SEVERITIES default broadened to CRITICAL,HIGH,MEDIUM,LOW (was HIGH,CRITICAL) — scan output and notification counts now include MEDIUM and LOW out of the box; narrow it explicitly if you want quieter reports
    • Breaking: EXIT_CODE input removed — replace with FAIL_ON_SEVERITIES
    • New FAIL_ON_SEVERITIES input (default CRITICAL,HIGH) — comma-separated severities that trigger job failure; replaces EXIT_CODE. Set to "" to enable report-only mode (scan and notify without blocking the pipeline)
    • Both scans (SARIF and JSON) now use SEVERITIES to filter findings; severity counts in the notification and outputs reflect only the selected levels
    • New low output — number of LOW findings when LOW is included in SEVERITIES
    • Notification body now labels findings with the active SEVERITIES value and includes the LOW count
    • Notification STATUS reflects both infrastructure scan failures and FAIL_ON_SEVERITIES threshold breaches
    • Action now validates that FAIL_ON_SEVERITIES is a subset of SEVERITIES and fails fast (exit 2) on contradictory configs — without this guard, a severity present in FAIL_ON_SEVERITIES but missing from SEVERITIES would be filtered out at scan time and silently ignored by the fail check
    • Action now validates that every severity in SEVERITIES and FAIL_ON_SEVERITIES is one of UNKNOWN, LOW, MEDIUM, HIGH, CRITICAL and rejects empty SEVERITIES — typos no longer silently produce a green 0-finding job
    • UNKNOWN is now a first-class severity: included in the whitelist, exposed via the new unknown output, counted in the notification, and accepted in FAIL_ON_SEVERITIES
    • Severity counts and notification body are now dynamic — only the severities listed in SEVERITIES appear in the Mattermost Findings: line (e.g. SEVERITIES=CRITICAL,HIGH → Findings: CRITICAL=2 HIGH=0), matching the sister GitLab CI component (devops/pipelines/security)

[v7.2.1] - 2026-04-23

Fixed

  • trivy-claude-analysis
    • Advisory creation now works end-to-end. secrets.GITHUB_TOKEN cannot be granted repository-advisories scope (not a valid GITHUB_TOKEN permission key) and returns 403 on POST /repos/{owner}/{repo}/security-advisories — callers must pass an installation token minted from a GitHub App instead
    • Now passes SKIP_PERMISSIONS: 'true' to claude-agent so the action no longer pauses in CI waiting for interactive approval when Claude runs gh api --method POST

Added

  • claude-agent
    • New ALLOWED_TOOLS input — value passed to Claude Code --allowedTools to pre-approve specific tools in headless CI (e.g. Bash(gh api:*),Read)
    • New SKIP_PERMISSIONS input (default "false") — set to "true" to pass --dangerously-skip-permissions and auto-approve every tool call; takes precedence over ALLOWED_TOOLS

Changed

  • README
    • Two-job pattern example now uses actions/create-github-app-token@v2 to mint an installation token from a GitHub App and drops the invalid repository-advisories: write permission key
    • New Prerequisites subsection documents the required GitHub App (imio-advisory-app), repo/org secrets (ADVISORY_APP_ID, ADVISORY_APP_SECRET, ANTHROPIC_API_KEY), the security-review environment (required reviewers, branch policy), and the need to enable Private vulnerability reporting on each consuming repo
    • trivy-claude-analysis GITHUB_TOKEN input description updated to warn against passing secrets.GITHUB_TOKEN

[v7.2.0] - 2026-04-23

Added

  • claude-agent
    • New composite action wrapping anthropics/claude-code-action (SHA-pinned) for running a Claude Code agent in CI pipelines
    • Accepts a PROMPT, an optional newline-separated list of FILES to expose, a MODEL override (default claude-sonnet-4-6), and an optional GITHUB_TOKEN for GitHub API operations
    • Claude output is displayed in the GitHub Actions Step Summary
  • trivy-claude-analysis
    • New composite action that reads a Trivy JSON report and asks Claude to create one private draft GitHub security advisory per finding
    • Takes a JSON_FILE path (from trivy-scan-notify's json_file output in the same job, or from actions/download-artifact in a later job)
    • SEVERITIES input (default CRITICAL,HIGH) controls which severity levels are processed; append ,MEDIUM to include medium findings
    • Advisories are deduplicated against existing drafts and processed in CRITICAL → HIGH → MEDIUM order
    • Requires repository-advisories: write permission in the calling workflow
    • Enables a two-job manual-approval pattern: job 1 scans and uploads the JSON artifact, job 2 (gated by a GitHub Environment with required reviewers) downloads the exact artifact and runs Claude — no re-scan, no state drift, no EXIT_CODE: '0' hack

Changed

  • trivy-scan-notify
    • Now uploads the Trivy JSON report as a workflow artifact (14-day retention) in addition to the SARIF artifact
    • Exposes outputs critical, high, medium, json_file, and artifact_name for chaining with trivy-claude-analysis

[v7.1.0] - 2026-04-21

Added

  • trivy-scan-notify
    • New composite action wrapping aquasecurity/trivy-action for image, filesystem and IaC-config scans
    • Uploads SARIF to GitHub Code Scanning and archives it as a 14-day workflow artifact
    • Notifies on Mattermost with parsed CRITICAL/HIGH/MEDIUM finding counts
    • External actions SHA-pinned per the iMio security référentiel (§5.5)
  • trivy-sbom-notify
    • New composite action generating a CycloneDX (or SPDX) SBOM for a container image
    • Uploads the SBOM as a workflow artifact (90-day retention by default) and notifies on Mattermost

[v7.0.1] - 2026-04-21

Changed

  • mattermost-notify
    • Workflow actor (github.actor) is now displayed as Author at the top of every notification body

[v7.0.0] - 2026-04-21

Changed

  • mattermost-notify
    • Replaced MESSAGE input with TITLE, BODY, and STATUS inputs
    • Notifications now use Mattermost attachments with color-coded strips (green for success, red for failure), emoji, and a structured bold-field body
    • MATTERMOST_WEBHOOK_URL is now optional (default empty); if not provided the step is silently skipped
    • GitHub Actions run link is automatically appended to every notification
  • All notify actions
    • Consolidated duplicate success/failure notification steps into a single if: always() call to mattermost-notify
    • Branch name (github.ref_name) is now included in every notification body

[v6.1.1] - 2026-03-24

Fixed

  • deb-build-push-notify
    • Export GNUPGHOME so gpg imports the signing key into the correct tmpdir

[v6.1.0] - 2026-03-19

Changed

  • Hardened all actions following security recommendations (see PR #8).

[v6.0.0] - 2026-03-19

  • deb-build-push-notify (breaking change)
    • Replaced dpkg-sig with debsigs for Ubuntu 24.04 compatibility

[v5.1.0] - 2025-09-23

Changed

  • build-push-notify
    • Added optional PRE_BUILD_COMMAND input to run commands before the build (supports multiline)

Added

  • k8s-update-tag
    • New action to update component tags in Kubernetes values files, commit changes and push to a repository

[v5.0.1] - 2025-07-17

Changed

  • plone-package-test-notify
    • Added optional BUILDOUT_OPTIONS input

[v5.0.0] - 2025-06-18

Changed

  • plone-package-test-notify (breaking change)
    • install python with uv (only compatible with Python 3, if you still need Python 2, use v4)
      • Added BUILDOUT_COMMAND input
      • Added UV_VERSION input

[v4.1.1] - 2024-11-15

Changed

  • repository-dispatch-notify
    • allow to pass inputs on workflow dispatch event call

Fixed

  • repository-dispatch-notify
    • inputs escape
    • remove obsolete input

[v4.1] - 2024-10-22

Added

  • repository-dispatch-notify

[v4.0.1] - 2024-10-22

Fixed

  • plone-package-test-notify
    • cleanup useless environment variables
    • escape command on notification message

[v4.0.0] - 2024-10-01

Changed

  • plone-package-test-notify
    • Do not install Python if PYTHON_VERSION is not specified
  • plone-package-test-notify (breaking change)
    • Removed REQUIREMENTS_FILE input
    • Added INSTALL_DEPENDENCIES_COMMANDS input

[v3.9.6] - 2024-09-26

Changed

  • code-analysis-notify
    • Hyperlinks to GitHub on mattermost notification message
  • plone-package-test-notify
    • Hyperlinks to GitHub on mattermost notification message

[v3.9.5] - 2024-09-20

Added

  • Add gha workflow to update main release

[v3.9.4] - 2024-09-19

Changed

  • plone-package-test-notify
    • More info on mattermost notification message
    • Optional CACHE_KEY input

[v3.9.3] - 2024-08-13

Fixed

  • helm-release-notify
    • fix get-version

[v3.9.2] - 2024-08-13

Fixed

  • helm-release-notify
    • missing dependency
  • helm-test-notify
    • missing dependency

[v3.9.1] - 2024-08-13

Fixed

  • helm-release-notify
    • missing dependency
  • helm-test-notify
    • missing dependency

[v3.9] - 2024-08-13

Added

  • helm-release-notify
  • helm-test-notify

[v3.8] - 2024-08-08

Added

  • plone-theme-build-push-notify

[v3.7.2] - 2024-07-31

Fixed

  • rundeck-notify
    • missing dependency

[v3.7.1] - 2024-07-30

Fixed

  • deb-build-push-notify
    • missing dependency

[v3.7] - 2024-07-30

Changed

  • All actions
    • only install curl if not already present on system to speedup workflow

[v3.6.1] - 2024-07-29

Fixed

  • build-push-notify
    • only send tags on notification to avoid duplicates
  • rundeck-notify
    • hyperlink to github repository on notification message

[v3.6] - 2024-07-26

Added

  • mattermost-notify

[v3.5] - 2024-07-26

Changed

  • rundeck-notify
    • notification message is more explicit and includes a hyperlink to the rundeck job

[v3.4] - 2024-07-25

Changed

  • All actions
    • MATTERMOST_WEBHOOK_URL is now optional. If not specified, notifications won't be sent

Added

  • code-analysis-notify
  • plone-package-test-notify

[v3.3] - 2024-07-19

Added

  • build-push-notify and tag-notify
    • bump actions/checkout to v4
    • bump docker/setup-qemu-action to v3
    • bump docker/setup-buildx-action to v3

[v3.2] - 2024-07-18

Added

  • deb-build-push-notify
    • github branch name on notification message

[v3.1] - 2024-07-16

Changed

  • build-push-notify
    • TARGET optional parameter allows to set the target stage to build

Added

  • check-url-availibility

[v3.0] - 2024-07-15

Changed

  • tag-notify (breaking change)
    • Parameter NEW_IMAGE_TAG removed
    • Parameter NEW_IMAGE_TAGS added (one per line)

[v2.0] - 2024-07-11

Changed

  • build-push-notify (breaking change)
    • Parameter IMAGE_TAG removed
    • Parameter IMAGE_TAGS added (one per line)

[v1.1] - 2024-07-08

Added

  • deb-build-push-notify

[v1.0.1] - 2024-07-04

Fixed

rundeck-notify

  • Fail when http status code != 200

[v1.0] - 2024-07-04

Added

  • build-push-notify
  • rundeck-notify
  • tag-notify