Skip to content

Conversation

@ack-bot
Copy link
Collaborator

@ack-bot ack-bot commented Nov 23, 2025

Update to ACK runtime v0.54.1, code-generator v0.54.0



NOTE:
This PR increments the release version of service controller from v1.5.3 to v1.5.4

Once this PR is merged, release v1.5.4 will be automatically created for iam-controller

Please close this PR, if you do not want the new patch release for iam-controller


stdout for make build-controller:

building ack-generate ... ok.
==== building iam-controller ====
Copying common custom resource definitions into iam
Building Kubernetes API objects for iam
Generating deepcopy code for iam
Generating custom resource definitions for iam
Building service controller for iam
Running GO mod tidy
Generating RBAC manifests for iam
Running gofmt against generated code for iam
Updating additional GitHub repository maintenance files
==== building iam-controller release artifacts ====
Building release artifacts for iam-v1.5.4
Generating common custom resource definitions
Generating custom resource definitions for iam
Generating RBAC manifests for iam

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@ack-bot ack-bot added the prow/auto-gen PRs related to prow auto generation automation label Nov 23, 2025
@ack-prow ack-prow bot requested review from a-hilaly and knottnt November 23, 2025 08:38

jobs:
call-hydrate-go-proxy:
uses: aws-controllers-k8s/.github/.github/workflows/reusable-postsubmit.yaml@main

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Copilot Autofix

AI 1 day ago

The best way to fix this problem is to add an explicit permissions key to the workflow at the root level, with the minimal set of permissions required. Since the delegate job simply calls a reusable workflow, it is safest to set a restrictive default policy (such as contents: read). If the job or reusable workflow requires more permissions, those can be added specifically. For this example, adding the block:

permissions:
  contents: read

immediately after the name: line (and before on:) in .github/workflows/postsubmit.yaml is the correct approach. This change does not affect any existing workflow logic or outputs.


Suggested changeset 1
.github/workflows/postsubmit.yaml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/postsubmit.yaml b/.github/workflows/postsubmit.yaml
--- a/.github/workflows/postsubmit.yaml
+++ b/.github/workflows/postsubmit.yaml
@@ -1,4 +1,6 @@
 name: Hydrate Go Proxy
+permissions:
+  contents: read
 
 on:
   push:
EOF
@@ -1,4 +1,6 @@
name: Hydrate Go Proxy
permissions:
contents: read

on:
push:
Copilot is powered by AI and may make mistakes. Always verify output.
@ack-prow
Copy link

ack-prow bot commented Nov 23, 2025

@ack-bot: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
iam-verify-code-gen 81be127 link false /test iam-verify-code-gen

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@michaelhtm
Copy link
Member

/lgtm

@ack-prow ack-prow bot added the lgtm Indicates that a PR is ready to be merged. label Nov 24, 2025
@ack-prow
Copy link

ack-prow bot commented Nov 24, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ack-bot, michaelhtm

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ack-prow ack-prow bot added the approved label Nov 24, 2025
@ack-prow ack-prow bot merged commit c134a02 into main Nov 24, 2025
9 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved lgtm Indicates that a PR is ready to be merged. prow/auto-gen PRs related to prow auto generation automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants