-
Notifications
You must be signed in to change notification settings - Fork 59
Update to ACK runtime v0.54.1, code-generator v0.54.0
#252
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: ack-bot The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
|
||
| jobs: | ||
| call-hydrate-go-proxy: | ||
| uses: aws-controllers-k8s/.github/.github/workflows/reusable-postsubmit.yaml@main |
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 3 days ago
To fix the problem, you should add a permissions key to the workflow file, either at the workflow root (so it applies to all jobs by default) or at the specific job level. For single-job workflows, both approaches are equivalent, but setting it at the root makes it more immediately visible. The minimal starting point is to set permissions: {} (which disables all GITHUB_TOKEN permissions), or specify only those permissions actually needed by the job or the reusable workflow it invokes. Unless you know more granular requirements, permissions: read-all (maps to contents: read) is a safe default that prevents unnecessary write permissions. Modify .github/workflows/postsubmit.yaml near the top, after the name: field and before the on: field, to add:
permissions:
contents: readAlternatively, if you know no permissions are needed at all, use permissions: {}. But contents: read is required by most workflows.
No external libraries or complex changes are needed -- just the addition of the permissions block.
-
Copy modified lines R2-R3
| @@ -1,4 +1,6 @@ | ||
| name: Hydrate Go Proxy | ||
| permissions: | ||
| contents: read | ||
|
|
||
| on: | ||
| push: |
|
@ack-bot: The following test failed, say
Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
Update to ACK runtime
v0.54.1, code-generatorv0.54.0v0.54.0release notesv0.54.1release notesNOTE:
This PR increments the release version of service controller from
v1.6.3tov1.6.4Once this PR is merged, release
v1.6.4will be automatically created forrds-controllerPlease close this PR, if you do not want the new patch release for
rds-controllerstdout for
make build-controller:By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.