Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency pleo-io/centralized-templates to v19.0.3 #178

Merged

Conversation

pleo-bot-renovate
Copy link
Contributor

This PR contains the following updates:

Package Update Change
pleo-io/centralized-templates patch v19.0.0 -> v19.0.3

Release Notes

pleo-io/centralized-templates

v19.0.3

Compare Source

Release Notes
Move vulnerable secret to organization secrets (#​626)

A Slack webhook in deploy_k8s_primary_ecr.yaml was vulnerable, meaning anyone could POST to the webhook to spam #dev-general. GitHub security analysis also notified us of this.

The webhook was confirmed to lead to #dev-general in collaboration with Security and SRE and has also been regenerated properly in the pleo Slack workspace.

The webhook in the workflow is moved to an organization secret instead of being available in plain text.


🐞 Fixes
Authors: 1

v19.0.2

Compare Source

Release Notes
Ensure Docker images are only built when deployed (#​627)

This ensures that Docker image builds are only performed as part of releasing a repository that should be deployed - in other words: repositories that have deploymentEnabled: true.

deploymentEnabled is currently set to true by default, unless otherwise overridden in the .github/templates.yaml repository configuration.

This allows Kotlin libraries to release and allows moons not ready for deployment to skip a redundant build of a container image that's never pushed to ECR or deployed.


🐞 Fixes
⚠️ Pushed to main
Authors: 3

v19.0.1

Compare Source

🐞 Fixes
Authors: 1


Configuration

📅 Schedule: Branch creation - "after 8am and before 5pm every weekday" (UTC), Automerge - "after 8am and before 5pm every weekday" (UTC).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@pleo-bot-renovate pleo-bot-renovate requested a review from a team as a code owner February 1, 2023 08:06
@pleo-bot-renovate pleo-bot-renovate added automerge dependencies Pull requests that update a dependency file patch labels Feb 1, 2023
@pleo-bot-renovate pleo-bot-renovate enabled auto-merge (squash) February 1, 2023 08:06
@pleo-bot-renovate
Copy link
Contributor Author

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.

Copy link
Contributor

@andersfischernielsen andersfischernielsen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good bot!

@pleo-bot-renovate pleo-bot-renovate merged commit d75fed1 into main Feb 2, 2023
@pleo-bot-renovate pleo-bot-renovate deleted the dependencies/pleo-io-centralized-templates-19.x branch February 2, 2023 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
automerge dependencies Pull requests that update a dependency file patch
Development

Successfully merging this pull request may close these issues.

None yet

3 participants