- setup-git-auth
- New action. Configures authenticated git access to
github.comfor the whole job viahttp.https://github.com/.extraheader(the same mechanismactions/checkoutuses), so tools that clone other repositories mid-job (mr.developer, git submodules,go get,pip install git+...) no longer clone anonymously. Sources declared with an SSH URL are rewritten to authenticated HTTPS through tokenlessinsteadOfentries MODEinput (defaultsetup) —cleanupremoves the credentials again. Composite actions cannot declare apost:step, so teardown is an explicit second call, typically withif: always()GITHUB_TOKENinput — required whenMODEissetup. Both the token and its base64 form are passed to::add-mask::, since a composite-action input is auto-masked only when the caller passed an actual secret
- New action. Configures authenticated git access to
- plone-package-test-notify
- New optional
GITHUB_TOKENinput — when set, the action callssetup-git-authright after the checkout and cleans up at the end, somr.developersource checkouts are authenticated instead of anonymous. Fixes intermittentfatal: could not read Username for 'https://github.com': No such device or addressbuildout failures caused by GitHub answering anonymous clones with a401, and allows private sources. PassGITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}; leaving it unset keeps the previous anonymous behaviour
- New optional
- helm-release-notify
- Optional GPG provenance signing (see https://helm.sh/docs/topics/provenance/). When
SIGNER_KEYis provided, the chart is packaged withhelm package --signand the resulting<chart>-<version>.tgz.provis published togh-pagesnext to the.tgz, so consumers can runhelm install/pull --verify - New
SIGNER_KEYinput — GPG private key (base64 encoded) used to sign the chart. If empty, the chart is published unsigned (unchanged behavior) - New
SIGNER_KEY_IDinput — GPG key fingerprint/ID used to export the legacy signing keyring; required whenSIGNER_KEYis set - New
SIGNER_KEY_PASSPHRASEinput — passphrase for the GPG signing key; required whenSIGNER_KEYis set - Mattermost notification body now includes a
Signed:line
- Optional GPG provenance signing (see https://helm.sh/docs/topics/provenance/). When
- helm-release-notify
- Replaced the third-party
tylerauerbeck/helm-gh-pagesDocker action with an inline publish step (Helm installed fromget.helm.sh; chart located, dependencies resolved, linted, packaged, and pushed togh-pagesin-action). The publishedindex.yamlURL scheme andtest/stableTARGET_DIRlayout are preserved, so existing unsigned callers are unaffected
- Replaced the third-party
- trivy-scan-notify
- Breaking:
SEVERITYinput renamed toSEVERITIES— update callers accordingly SEVERITIESdefault broadened toCRITICAL,HIGH,MEDIUM,LOW(wasHIGH,CRITICAL) — scan output and notification counts now include MEDIUM and LOW out of the box; narrow it explicitly if you want quieter reports- Breaking:
EXIT_CODEinput removed — replace withFAIL_ON_SEVERITIES - New
FAIL_ON_SEVERITIESinput (defaultCRITICAL,HIGH) — comma-separated severities that trigger job failure; replacesEXIT_CODE. Set to""to enable report-only mode (scan and notify without blocking the pipeline) - Both scans (SARIF and JSON) now use
SEVERITIESto filter findings; severity counts in the notification and outputs reflect only the selected levels - New
lowoutput — number of LOW findings whenLOWis included inSEVERITIES - Notification body now labels findings with the active
SEVERITIESvalue and includes the LOW count - Notification STATUS reflects both infrastructure scan failures and
FAIL_ON_SEVERITIESthreshold breaches - Action now validates that
FAIL_ON_SEVERITIESis a subset ofSEVERITIESand fails fast (exit 2) on contradictory configs — without this guard, a severity present inFAIL_ON_SEVERITIESbut missing fromSEVERITIESwould be filtered out at scan time and silently ignored by the fail check - Action now validates that every severity in
SEVERITIESandFAIL_ON_SEVERITIESis one ofUNKNOWN,LOW,MEDIUM,HIGH,CRITICALand rejects emptySEVERITIES— typos no longer silently produce a green 0-finding job UNKNOWNis now a first-class severity: included in the whitelist, exposed via the newunknownoutput, counted in the notification, and accepted inFAIL_ON_SEVERITIES- Severity counts and notification body are now dynamic — only the severities listed in
SEVERITIESappear in the MattermostFindings:line (e.g.SEVERITIES=CRITICAL,HIGH→Findings: CRITICAL=2 HIGH=0), matching the sister GitLab CI component (devops/pipelines/security)
- Breaking:
- trivy-claude-analysis
- Advisory creation now works end-to-end.
secrets.GITHUB_TOKENcannot be grantedrepository-advisoriesscope (not a validGITHUB_TOKENpermission key) and returns 403 onPOST /repos/{owner}/{repo}/security-advisories— callers must pass an installation token minted from a GitHub App instead - Now passes
SKIP_PERMISSIONS: 'true'toclaude-agentso the action no longer pauses in CI waiting for interactive approval when Claude runsgh api --method POST
- Advisory creation now works end-to-end.
- claude-agent
- New
ALLOWED_TOOLSinput — value passed to Claude Code--allowedToolsto pre-approve specific tools in headless CI (e.g.Bash(gh api:*),Read) - New
SKIP_PERMISSIONSinput (default"false") — set to"true"to pass--dangerously-skip-permissionsand auto-approve every tool call; takes precedence overALLOWED_TOOLS
- New
- README
- Two-job pattern example now uses
actions/create-github-app-token@v2to mint an installation token from a GitHub App and drops the invalidrepository-advisories: writepermission key - New Prerequisites subsection documents the required GitHub App (
imio-advisory-app), repo/org secrets (ADVISORY_APP_ID,ADVISORY_APP_SECRET,ANTHROPIC_API_KEY), thesecurity-reviewenvironment (required reviewers, branch policy), and the need to enable Private vulnerability reporting on each consuming repo trivy-claude-analysisGITHUB_TOKENinput description updated to warn against passingsecrets.GITHUB_TOKEN
- Two-job pattern example now uses
- claude-agent
- New composite action wrapping
anthropics/claude-code-action(SHA-pinned) for running a Claude Code agent in CI pipelines - Accepts a
PROMPT, an optional newline-separated list ofFILESto expose, aMODELoverride (defaultclaude-sonnet-4-6), and an optionalGITHUB_TOKENfor GitHub API operations - Claude output is displayed in the GitHub Actions Step Summary
- New composite action wrapping
- trivy-claude-analysis
- New composite action that reads a Trivy JSON report and asks Claude to create one private draft GitHub security advisory per finding
- Takes a
JSON_FILEpath (fromtrivy-scan-notify'sjson_fileoutput in the same job, or fromactions/download-artifactin a later job) SEVERITIESinput (defaultCRITICAL,HIGH) controls which severity levels are processed; append,MEDIUMto include medium findings- Advisories are deduplicated against existing drafts and processed in CRITICAL → HIGH → MEDIUM order
- Requires
repository-advisories: writepermission in the calling workflow - Enables a two-job manual-approval pattern: job 1 scans and uploads the JSON artifact, job 2 (gated by a GitHub Environment with required reviewers) downloads the exact artifact and runs Claude — no re-scan, no state drift, no
EXIT_CODE: '0'hack
- trivy-scan-notify
- Now uploads the Trivy JSON report as a workflow artifact (14-day retention) in addition to the SARIF artifact
- Exposes outputs
critical,high,medium,json_file, andartifact_namefor chaining withtrivy-claude-analysis
- trivy-scan-notify
- New composite action wrapping
aquasecurity/trivy-actionfor image, filesystem and IaC-config scans - Uploads SARIF to GitHub Code Scanning and archives it as a 14-day workflow artifact
- Notifies on Mattermost with parsed CRITICAL/HIGH/MEDIUM finding counts
- External actions SHA-pinned per the iMio security référentiel (§5.5)
- New composite action wrapping
- trivy-sbom-notify
- New composite action generating a CycloneDX (or SPDX) SBOM for a container image
- Uploads the SBOM as a workflow artifact (90-day retention by default) and notifies on Mattermost
- mattermost-notify
- Workflow actor (
github.actor) is now displayed as Author at the top of every notification body
- Workflow actor (
- mattermost-notify
- Replaced
MESSAGEinput withTITLE,BODY, andSTATUSinputs - Notifications now use Mattermost attachments with color-coded strips (green for success, red for failure), emoji, and a structured bold-field body
MATTERMOST_WEBHOOK_URLis now optional (default empty); if not provided the step is silently skipped- GitHub Actions run link is automatically appended to every notification
- Replaced
- All notify actions
- Consolidated duplicate success/failure notification steps into a single
if: always()call tomattermost-notify - Branch name (
github.ref_name) is now included in every notification body
- Consolidated duplicate success/failure notification steps into a single
- deb-build-push-notify
- Export GNUPGHOME so gpg imports the signing key into the correct tmpdir
- Hardened all actions following security recommendations (see PR #8).
- deb-build-push-notify (breaking change)
- Replaced dpkg-sig with debsigs for Ubuntu 24.04 compatibility
- build-push-notify
- Added optional PRE_BUILD_COMMAND input to run commands before the build (supports multiline)
- k8s-update-tag
- New action to update component tags in Kubernetes values files, commit changes and push to a repository
- plone-package-test-notify
- Added optional BUILDOUT_OPTIONS input
- plone-package-test-notify (breaking change)
- install python with uv (only compatible with Python 3, if you still need Python 2, use v4)
- Added BUILDOUT_COMMAND input
- Added UV_VERSION input
- install python with uv (only compatible with Python 3, if you still need Python 2, use v4)
- repository-dispatch-notify
- allow to pass inputs on workflow dispatch event call
- repository-dispatch-notify
- inputs escape
- remove obsolete input
- repository-dispatch-notify
- plone-package-test-notify
- cleanup useless environment variables
- escape command on notification message
- plone-package-test-notify
- Do not install Python if PYTHON_VERSION is not specified
- plone-package-test-notify (breaking change)
- Removed REQUIREMENTS_FILE input
- Added INSTALL_DEPENDENCIES_COMMANDS input
- code-analysis-notify
- Hyperlinks to GitHub on mattermost notification message
- plone-package-test-notify
- Hyperlinks to GitHub on mattermost notification message
- Add gha workflow to update main release
- plone-package-test-notify
- More info on mattermost notification message
- Optional CACHE_KEY input
- helm-release-notify
- fix get-version
- helm-release-notify
- missing dependency
- helm-test-notify
- missing dependency
- helm-release-notify
- missing dependency
- helm-test-notify
- missing dependency
- helm-release-notify
- helm-test-notify
- plone-theme-build-push-notify
- rundeck-notify
- missing dependency
- deb-build-push-notify
- missing dependency
- All actions
- only install curl if not already present on system to speedup workflow
- build-push-notify
- only send tags on notification to avoid duplicates
- rundeck-notify
- hyperlink to github repository on notification message
- mattermost-notify
- rundeck-notify
- notification message is more explicit and includes a hyperlink to the rundeck job
- All actions
- MATTERMOST_WEBHOOK_URL is now optional. If not specified, notifications won't be sent
- code-analysis-notify
- plone-package-test-notify
- build-push-notify and tag-notify
- bump actions/checkout to v4
- bump docker/setup-qemu-action to v3
- bump docker/setup-buildx-action to v3
- deb-build-push-notify
- github branch name on notification message
- build-push-notify
- TARGET optional parameter allows to set the target stage to build
- check-url-availibility
- tag-notify (breaking change)
- Parameter NEW_IMAGE_TAG removed
- Parameter NEW_IMAGE_TAGS added (one per line)
- build-push-notify (breaking change)
- Parameter IMAGE_TAG removed
- Parameter IMAGE_TAGS added (one per line)
- deb-build-push-notify
- Fail when http status code != 200
- build-push-notify
- rundeck-notify
- tag-notify