From ad24f933f9a039975bdd8dfa9b40f0bd3e3d9845 Mon Sep 17 00:00:00 2001 From: Duynh ne Date: Sun, 16 Aug 2026 10:58:07 +0700 Subject: [PATCH] Pin gha-workflows workflows to v1.0.2 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Every reusable workflow here sat on a mix of v1.0.0 and v1.0.1. v1.0.2 skips the two secret-dependent jobs on Dependabot runs, which is what paints every dependency PR red today: the Dependabot secrets store has no SONAR_TOKEN or SLACK_BOT_TOKEN, so those jobs can never pass there. This moves all thirteen references to v1.0.2 in one step rather than letting Dependabot walk them to v1.0.1 first — that intermediate version does not carry the fix, so the wave after it would be red as well. The rest of the v1.0.0 to v1.0.2 delta is a codeql-action/upload-sarif patch bump and a new backward-compatible go-check input. The release path — docker-build-go, docker-sign, goreleaser — is byte-identical. --- .github/workflows/build.yml | 16 ++++++++-------- .github/workflows/check.yml | 10 +++++----- 2 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 461b608..545d067 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -15,7 +15,7 @@ permissions: jobs: go-check: - uses: duynhlab/gha-workflows/.github/workflows/go-check.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/go-check.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: command-test: 'go test -race -coverprofile=coverage.out ./...' lint: true @@ -23,14 +23,14 @@ jobs: integration-command: 'go test -tags=integration -covermode=atomic -coverprofile=coverage-integration.out ./internal/core/repository/...' gitleaks: - uses: duynhlab/gha-workflows/.github/workflows/gitleaks.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/gitleaks.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 permissions: contents: read security-events: write sonar: needs: [go-check, gitleaks] - uses: duynhlab/gha-workflows/.github/workflows/sonarqube.yml@b271f01094ee7f16271b14575539e62907a50724 # v1.0.0 + uses: duynhlab/gha-workflows/.github/workflows/sonarqube.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: project-key: 'duynhlab_${{ github.event.repository.name }}' organization: 'duynhlab' @@ -41,7 +41,7 @@ jobs: docker-build: needs: [go-check, sonar] - uses: duynhlab/gha-workflows/.github/workflows/docker-build-go.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/docker-build-go.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: image-name: ${{ github.event.repository.name }} push: true @@ -56,7 +56,7 @@ jobs: trivy-report: needs: [docker-build] if: needs.docker-build.outputs.scan-status == 'pass' - uses: duynhlab/gha-workflows/.github/workflows/trivy-scan.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/trivy-scan.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: image-ref: ghcr.io/${{ github.repository }}/${{ github.event.repository.name }}@${{ needs.docker-build.outputs.digest }} severity: 'CRITICAL,HIGH,MEDIUM' @@ -73,7 +73,7 @@ jobs: docker-sign: needs: [docker-build] - uses: duynhlab/gha-workflows/.github/workflows/docker-sign.yml@b271f01094ee7f16271b14575539e62907a50724 # v1.0.0 + uses: duynhlab/gha-workflows/.github/workflows/docker-sign.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: tags: ${{ needs.docker-build.outputs.tags }} digest: ${{ needs.docker-build.outputs.digest }} @@ -87,7 +87,7 @@ jobs: release-binary: needs: [go-check, sonar] if: startsWith(github.ref, 'refs/tags/v') - uses: duynhlab/gha-workflows/.github/workflows/goreleaser.yml@b271f01094ee7f16271b14575539e62907a50724 # v1.0.0 + uses: duynhlab/gha-workflows/.github/workflows/goreleaser.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 permissions: contents: write id-token: write @@ -95,7 +95,7 @@ jobs: notify: if: always() needs: [go-check, gitleaks, sonar, docker-build, trivy-report, docker-sign, release-binary] - uses: duynhlab/gha-workflows/.github/workflows/status.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/status.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: slack_channel_id: "C0AD82A9A74" gsheet_spreadsheet_id: "1F2VUrAOyMGnETApp5yA-ldCW81ConiQXnWYZVxKas_0" diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index 7008a05..ad386e9 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -11,14 +11,14 @@ permissions: jobs: pr-checks: - uses: duynhlab/gha-workflows/.github/workflows/pr-checks.yml@b271f01094ee7f16271b14575539e62907a50724 # v1.0.0 + uses: duynhlab/gha-workflows/.github/workflows/pr-checks.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: slack_channel_id: "C0AD82A9A74" secrets: SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }} go-check: - uses: duynhlab/gha-workflows/.github/workflows/go-check.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/go-check.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: command-test: 'go test -race -coverprofile=coverage.out ./...' lint: true @@ -26,14 +26,14 @@ jobs: integration-command: 'go test -tags=integration -covermode=atomic -coverprofile=coverage-integration.out ./internal/core/repository/...' gitleaks: - uses: duynhlab/gha-workflows/.github/workflows/gitleaks.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/gitleaks.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 permissions: contents: read security-events: write sonar: needs: [go-check, gitleaks] - uses: duynhlab/gha-workflows/.github/workflows/sonarqube.yml@b271f01094ee7f16271b14575539e62907a50724 # v1.0.0 + uses: duynhlab/gha-workflows/.github/workflows/sonarqube.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: project-key: 'duynhlab_${{ github.event.repository.name }}' organization: 'duynhlab' @@ -47,7 +47,7 @@ jobs: # fail there — skip instead of painting every deps PR red. if: always() && github.actor != 'dependabot[bot]' needs: [pr-checks, go-check, gitleaks, sonar] - uses: duynhlab/gha-workflows/.github/workflows/status.yml@6b1c155968c3212b10f0415a07e6e8e3cf04d5a9 # v1.0.1 + uses: duynhlab/gha-workflows/.github/workflows/status.yml@725eb66998f03be252de9b11ef4bb530e59b9dd7 # v1.0.2 with: slack_channel_id: "C0AD82A9A74" slack_thread_ts: ${{ needs.pr-checks.outputs.slack_thread_ts }}