-
Notifications
You must be signed in to change notification settings - Fork 85
Update to ACK runtime v0.54.1, code-generator v0.54.0
#193
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
|
||
| jobs: | ||
| call-hydrate-go-proxy: | ||
| uses: aws-controllers-k8s/.github/.github/workflows/reusable-postsubmit.yaml@main |
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 4 days ago
To address the issue, we should add a permissions block at the workflow level in .github/workflows/postsubmit.yaml, with minimal required permissions. Since the reusable workflow is being called via uses:, and unless there is evidence that it requires write permissions, we should use the least privilege principle. Typically, for workflows with no obvious write operations (such as publishing to contents or writing to issues/pull-requests), contents: read is an appropriate default. If later analysis shows that write access is needed for some scopes, those can be added. The permissions block should be inserted at the root level immediately below the name and before any on/jobs blocks.
-
Copy modified lines R2-R3
| @@ -1,4 +1,6 @@ | ||
| name: Hydrate Go Proxy | ||
| permissions: | ||
| contents: read | ||
|
|
||
| on: | ||
| push: |
|
@ack-bot: The following test failed, say
Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
a-hilaly
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: a-hilaly, ack-bot The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Update to ACK runtime
v0.54.1, code-generatorv0.54.0v0.54.0release notesv0.54.1release notesNOTE:
This PR increments the release version of service controller from
v1.1.2tov1.1.3Once this PR is merged, release
v1.1.3will be automatically created fors3-controllerPlease close this PR, if you do not want the new patch release for
s3-controllerstdout for
make build-controller:By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.