github cloudposse/atmos v1.231.0-rc.4

pre-release5 hours ago
feat(store): tags and expiration for Azure Key Vault store secrets @osterman (#3285) ## what
  • Adds tags (string map) and expires options to the Azure Key Vault store; both are applied to every secret Atmos writes.
  • expires takes either a relative duration (90d, 2160h, recalculated on each write) or a specific date (RFC 3339 or YYYY-MM-DD). Invalid values (e.g. 0d, soon) fail when the store is created; a past fixed date is accepted with a logged warning.
  • Parsing lives in a new azure_keyvault_expires.go with table-driven tests; Get/Has/Keys/Delete and stores that set neither option are unchanged.
  • Updates the stores configuration docs and the atmos-stores agent skill, and adds a blog post and a Secrets Management roadmap milestone.

why

  • Organizations that enforce an Azure Policy requiring tags and an expiration date on every Key Vault secret could not use Azure Key Vault as an Atmos store, because Atmos wrote only the secret value and the policy rejected the write.
  • A single expires field accepting a duration or a date avoids two overlapping options, and the relative form never goes stale the way a fixed date eventually does.

references

Summary by CodeRabbit

  • New Features
    • Azure Key Vault secrets can include configured tags and expiration when written. Expiration accepts durations of at least one second, RFC 3339 timestamps, and dates; relative durations are recalculated on each write.
    • Invalid expiration values are rejected when the store is created. Past fixed expiration dates are accepted with a warning.
  • Bug Fixes
    • Signature verification retries a specific Windows socket-access failure; other permission errors remain non-retryable.
  • Documentation
    • Added Azure Key Vault configuration guidance and updated links to YAML function documentation.
    • Documented the Windows signature-verification retry behavior.
feat(backend): add bucket_namespace option for S3 state bucket provisioning @osterman (#3288) ## what
  • Add an optional provision.backend.bucket_namespace setting. The S3 backend provisioner sends it as the BucketNamespace parameter of the S3 CreateBucket call when it creates a state bucket.
  • Validate the value against the namespaces the AWS SDK defines (read from the SDK enum, so Atmos keeps no list of its own) before any AWS call is made. A non-string value is rejected earlier with its own error.
  • Read the option from provision.backend, so it never appears in the generated Terraform backend config. Other backend types ignore it at runtime, and omitting it leaves existing behavior unchanged.
  • Scope the manifest schema to Terraform components: the setting lives in a new terraform-only terraform_provision definition, and manifest validation rejects it when backend_type is set to anything other than s3 (an unset or !included backend_type is not checked).
  • Add docs, a changelog post, a roadmap milestone, and tests. Also fix a broken Docusaurus anchor in scaffold validate that the website build reported.

why

  • Amazon S3 offers an account-scoped bucket namespace that reserves bucket names to the owning account, avoiding name collisions and name reuse after deletion. It is selected by a parameter on the creation request, which Atmos never sent, so teams that want it had to bootstrap state buckets outside Atmos.
  • Passing the value through, with validation against the SDK's own values, keeps Atmos free of any naming convention or account/region assumptions.
  • The shared provision schema definition also feeds Kubernetes, Helm, and other component types, so the S3-only setting needed its own terraform-scoped definition.

references

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added optional S3 backend bucket namespace configuration. Set it to global or account-regional to control the namespace used when Atmos creates a bucket; leaving it unset preserves existing behavior. The setting applies only to S3 and is not included in generated Terraform backend configuration.
  • Bug Fixes
    • Invalid namespace types and unsupported values are now rejected with clear errors before AWS requests are made.
  • Documentation
    • Added guidance on configuring bucket namespaces and updated a scaffold documentation link.
fix(docs): preserve sidebar context and explain component/workflow names @osterman (#3291) ## what
  • Preserve clicked sidebar entries, expanded branches, and scroll position across shared links, cross-section return trails, browser Back/Forward, filtering, and mobile navigation while keeping All reference available.
  • Link component and workflow <name> categories and overview pages to naming guides covering YAML keys, CLI usage, dependencies, implementation paths, scope, and file disambiguation, and improve active-link contrast in dark mode.

why

  • Keep Workflows → Steps → Back anchored to the original article and Terraform → <name> → dependencies/retry anchored to the clicked branch, while making placeholder names understandable without changing canonical URLs, breadcrumbs, schemas, or runtime naming rules.

references

  • Validation: 56 navigation tests passing (including early hydration toggles and consecutive expansion updates); naming examples validated against the manifest schema; agent-browser desktop/mobile, history, filtering, keyboard, and new-tab checks passed; sidebar accessibility audit reported zero violations; documentation build passed with release-history scans skipped and an existing unrelated scaffold-anchor warning.

Summary by CodeRabbit

  • Documentation

    • Added guidance on naming workflow and component instances, including how names are used in commands, dependencies, and implementation paths.
    • Added links to naming guidance from the relevant workflow and component navigation pages.
  • New Features

    • Sidebar navigation now includes Back and All controls, remembers navigation and scroll position, and restores the selected section when navigating through browser history.
    • Sidebar categories link to their documentation, and search filtering retains matching navigation items.
fix(website): unblock prod deploy; build website in merge queue @osterman (#3287) ## what
  • Add related_docs front matter to examples/scaffolding-yaml-functions/README.md (links to scaffold generate, scaffold validate, and the !include function).
  • Add a merge_group trigger to Website Preview Build so the website prebuild tests and the Docusaurus build also run against the synthetic merge-queue commit. The preview deploy still ignores these runs because they have no associated PR number.

why

  • The Website Deploy Prod run for bd75d3bc88 failed in the build step, so atmos.tools has been stale since #3195 (last good deploy). The example-docs prebuild test added in #3272 requires every example README to declare at least two related_docs, and the example added in #3230 had none. Each PR passed on its own; they only conflict once combined.
  • The merge queue only runs CodeQL, Tests, Validate Codeowners, and Verify Symlinks. The website build was pull_request-only, so nothing validated the combined result before it reached main. The concurrency block on the deploy workflow only serializes deploys; it does not validate content.
  • To make the new job block merges, add it as a required check in the Merge Queue ruleset. That is a repo setting and is not changed here.

references

Summary by CodeRabbit

  • Chores
    • Website preview builds now also run for merge-queue checks.
  • Documentation
    • Added links to documentation for scaffold generation, template configuration, scaffold validation, and the !include YAML function.
docs: improve navigation, command intros, and example guides @osterman (#3272) ## what
  • Align Stack Configuration with supported YAML scopes, canonical references, status dots, component-library navigation and overviews generated from reusable sidebar_group front matter, and YAML-shaped workflow navigation; reorganize Reference around CLI essentials, capabilities, configuration, automation, and resources, with prominent CI/CD navigation and dedicated GitHub Actions guides.
  • Improve Learn navigation, tutorial callouts, all command introductions, the container overview, sidebar filtering and spacing, and terminal rendering; use front-matter references and inline documentation links across all 72 examples, unwrap the GitOps demo into built-in commands, and isolate AI toolchain tests from public registries.

why

  • Make commands and CI workflows easier to find, explain configuration scopes and feature use cases, and preserve existing public URLs and historical CI anchors.

references

  • Validation: 38 navigation tests, Intro coverage across all 369 command pages, example link coverage and GitOps recording validation, 29 terminal regression tests, production website build, commit hooks, desktop/mobile browser checks, and AI toolchain tests with network access blocked.
feat(scaffold): !include and other YAML functions in scaffold.yaml @jorrite (#3230) ## what
  • scaffold.yaml now resolves a shared set of Atmos YAML functions, not just !include: !include/!include.raw, !env, !random, !cwd, the !git.*/!repo-root family, and !literal — anywhere a scaffold manifest currently accepts a literal value: options:, a type: computed field's value:, or a matrix: axis.
  • Resolution happens via one shared, policy-driven tag walker (pkg/utils.WalkYAMLTags/TagWalkPolicy) that both the stack-manifest loader and scaffold's own ScaffoldTagPolicy go through — not a bespoke, scaffold-only walker.
  • Any tag that needs real stack/component/backend context (!terraform.state, !store, !secret, etc.) is rejected outright with a clear error naming it, instead of silently deferred to a later phase scaffold.yaml has none of.
  • A locally-included file is excluded from generated output automatically, the same way scaffold.yaml itself is.
  • atmos scaffold validate resolves all of this too, not just generate, so a missing file, bad filter, or malformed function call is caught before anyone runs generate.
  • Docs (generate.mdx), blog post, roadmap entry, and example (examples/scaffolding-yaml-functions, renamed from scaffolding-include) updated to demonstrate !include plus !git.branch and !env.

why

  • Small pieces of reference data (license choices, region codes, a naming-convention lookup table) show up constantly in real scaffold templates and rarely stay confined to one field — until now, that table had nowhere to live but inside scaffold.yaml itself, copied into every field that needed it. !include already solves this for stack manifests; extending it to scaffold manifests reuses a mechanism users already know.
  • The original implementation added a bespoke !include-only tag walker, duplicating the stack-manifest loader's own dispatch logic. Refactored into one shared walker instead, so supporting more of Atmos's YAML function catalog didn't mean reinventing dispatch a third time.

A note on !exec

An earlier version of this PR included !exec in the expanded tag set. A field-test pass against the real binary found that was a real RCE risk, not a theoretical one: scaffold.yaml is resolved for every configured template just to show its name/description in atmos scaffold list and the interactive template picker — not only the one a user actually selects or generates. With !exec supported, simply running atmos scaffold list would silently execute a shell command from any configured template, including a shared or vendored one, with no generate, --force, or confirmation involved (confirmed live with a working touch-based proof-of-execution). !exec is removed entirely as a result; every other context-free tag is unaffected.

Fixes found during review

  • An embedded (built-in) template's local !include target could resolve relative to the process's CWD instead of failing cleanly, since the internal "embedded" marker was passed around as if it were a real directory.
  • A remote-fetched template's (oci://, git::, https://, s3://) local !include always failed generation: the real fetch directory gets overwritten with the original remote reference string right after fetching (for display/provenance), and a later re-parse of the same scaffold.yaml was using that overwritten value instead of the real, still-alive directory.
  • A transitively-included file's own !include tag was confirmed unreachable: !include's fetch decodes the included file's content generically, and a custom YAML tag doesn't survive that decode. Documented the actual (pre-existing, shared with stack manifests) limitation rather than "fixing" something that was never reachable -- and, per a later review pass, added that same explanation to the user-facing docs (generate.mdx), not just the internal doc comment.

references

  • Follow-up to #3222 (type: computed fields), which this PR builds on and which merged as e42695003.
  • Docs: generate.mdx#loading-external-data-with-include-and-other-yaml-functions
  • Blog post: website/blog/2026-10-01-scaffold-include.mdx
  • Example: examples/scaffolding-yaml-functions

Summary by CodeRabbit

  • New Features
    • Scaffold templates resolve supported YAML functions—including includes, environment and Git values, random values, working-directory values, and literals—before schema validation.
    • Included local files can provide options, computed values, and matrix axes without being copied into generated projects. Includes in fetched remote templates resolve relative to the fetched template.
    • Scaffold validation resolves includes and reports missing sources or values that fail schema validation. Functions requiring stack, component, or backend context, as well as !exec, are unsupported.
  • Performance
    • Large text changes are processed more efficiently during generation.
  • Documentation
    • Added guidance and an example covering YAML functions in scaffold templates.

🚀 Enhancements

fix: tailor upgrade hints to the Atmos installation method @osterman (#3293) ## what
  • Tailor Atmos upgrade notices to the detected installation method, with a separate implementation per installer in pkg/installer and rendering in pkg/upgrade, replacing the utils helper.
  • Add detection, timeout, structured-output, and stderr snapshot tests plus documentation while preserving update-check timing and stdout behavior.

why

  • The existing notice always suggested Atmos's native installer, which could create a second installation; manager-specific guidance now respects version pins, treats DEB/RPM/APK repository availability as conditional, and falls back to installation documentation when ownership is unknown.

references

  • Version-check documentation
  • Validation: focused version-command tests, race-enabled installer/renderer tests, Windows/Linux cross-compilation, atmos lint --changed, and the website production build; installer coverage 93.4%, renderer coverage 100%.

Summary by CodeRabbit

  • New Features
    • Update notices now show installation-specific upgrade guidance, including package-manager commands, version-manager steps, or a releases-page link.
    • Atmos detects common package-manager, version-manager, and native toolchain installations using read-only checks with a short time limit.
    • Installation-specific guidance appears in automatic notices and atmos version --check. JSON and YAML output remain free of notices.
  • Documentation
    • Added information about upgrade notices, supported installation types, and detection behavior.
fix(git): keep-history init no longer requires branch in source @bonddim (#3255) ## what
  • With init.keep_history: true, atmos git init now clones init.from at its default branch, then creates the configured branch with git checkout -B. The configured branch no longer has to exist in the source repository.
  • Corrected the atmos git init docs, which said the branch had to exist in the source.

why

  • In keep-history mode, Atmos ran git clone --branch <branch> against init.from using the destination repository's branch. That branch belongs to the target repo, so the clone failed with fatal: Remote branch init not found in upstream origin.
  • keep_history: false already treats branch as the name of the new history. Keep-history mode now does the same, while still preserving the source history and keeping the source as the upstream remote.

Behavior change: if the configured branch also existed in the source (e.g. both use develop), keep-history init used to seed from that branch. It now seeds from the source's default branch.

references

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Git Initialization

    • Seeding now starts from the source repository’s default branch in both history modes.
    • In keep-history mode, the configured destination branch is created or reset at the cloned commit, so it no longer needs to exist in the source repository.
    • Fresh-history mode continues to use a shallow clone.
  • Documentation

    • Updated the git init guide to reflect how keep-history mode handles the configured branch.
fix(scaffold): stop leaking internal gitref-probe step name into spinner @jorrite (#3279) ## What

atmos scaffold generate briefly showed an internal step identifier in its spinner text when fetching a //subdir git source:

⣻  Fetching scaffold template `gitref-probe` ...

resolveSubdirGitRef (in pkg/generator/source/resolver.go) does a throwaway probe fetch into a temp directory purely to pre-resolve the commit for a //subdir git source before the real content fetch runs (see pinSubdirGitSource's doc comment). That probe fetch passed the internal literal "gitref-probe" as the spinner's displayed template name instead of the actual template name.

Why

The literal "gitref-probe" is an internal identifier for the probe step, not something a user should ever see. It leaked into user-facing spinner output.

Fix

Thread the real template name through pinSubdirGitSource → resolveSubdirGitRef → fetchRemoteSource, so the probe fetch's spinner shows the same user-facing label (Fetching scaffold template `<name>`) as the real content fetch that follows it, instead of the internal step name.

Scope check: grepped the rest of the scaffold generate path (pkg/generator/) for other spinner/progress messages — resolver.go's fetchRemoteSource is the only one, and it's now fixed. No other instance of this class of bug was found in that path.

References

  • pkg/generator/source/resolver.go
  • docs/fixes/2026-10-06-scaffold-gitref-probe-spinner-label.md

Test plan

  • go build ./...
  • go vet ./pkg/generator/...
  • Updated the three existing unit tests that call pinSubdirGitSource/resolveSubdirGitRef directly to pass a template name
  • Manually ran atmos scaffold generate against a local git:: //subdir source and confirmed the spinner no longer shows gitref-probe — it now shows the real source/name on both the probe and content fetch

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes
    • Git-based template generation now displays the template name consistently during both the preliminary check and content fetch, instead of showing “gitref-probe.”
fix(agent-skills): track the Claude Code plugin version via Version Tracker @osterman (#3195) ## what
  • Track cloudposse/atmos's own latest release as a Version Tracker dependency (version.dependencies.atmos in atmos.yaml, locked in versions.lock.yaml).
  • Write that version into agent-skills/.claude-plugin/plugin.json and .claude-plugin/marketplace.json (top-level and the atmos plugin entry, which had no version before) using the json file manager, with format: '{{ trimPrefix "v" .Version }}' so the manifests carry bare semver.
  • Backfill both manifests from 1.0.0 to the current release.
  • Add a plugin-version job to .github/workflows/build.yml (needs: docker) that runs atmos version track update and apply inside the image the docker job just pushed, then opens a no-release PR with the refreshed manifests and lock file. It replaced an earlier standalone registry_package-triggered workflow (removed): that trigger would likely never have fired, since the image is pushed with the default GITHUB_TOKEN and GitHub doesn't start workflow runs from events that token causes.
  • Remediate 3 Dependabot alerts found after pushing: containerd/containerd/v2 (#299, medium — OCI index graph amplification DoS), fast-uri (#300/#301, high — authority injection / host confusion), image-size (#297/#298, high — parser DoS). All patch/minor bumps within their existing major version.

why

  • plugin.json declared "version": "1.0.0" at every commit since it was added, and claude plugin update compares declared versions, so installed plugins could never pick up new skills. Installs from months ago still serve the original 21 skills while agent-skills/skills/ now has 52.
  • Claude Code's plugin cache is version-scoped, so a version bump is what triggers a fresh copy of the skills.
  • Version Tracker (the json manager and format field, both added upstream in Atmos itself while this PR was in progress) replaces the shell-and-sed approach this started as: no template/rendered file pairs, and the manifests stay single-source files.
  • The security fixes were opportunistic, triggered by GitHub's Dependabot scan of this branch's push.

references

  • closes #2895
  • Version Tracker fixes this depended on: #2900 (draft releases excluded from resolution), #2966 (json manager, explicit empty version.files), #3069 (format on set entries) — all landed upstream in Atmos itself during this PR
  • Dependabot alerts remediated: #297, #298, #299, #300, #301

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Updates
    • The Atmos Claude Code plugin and its marketplace listing now report version 1.229.0, matching the Atmos release.
    • Plugin version information is refreshed automatically following stable Atmos releases.
fix(toolchain): time out artifact downloads only when stalled @osterman (#3277) ## what
  • Replace the five-minute total deadline for PR/SHA/branch artifact downloads with an inactivity watchdog that resets on response headers and received bytes. Active transfers can continue beyond five minutes; caller deadlines still apply.

  • Report artifact download timed out: no download progress for 5m, clean up partial files after closing them, and retain redirect authentication protections.

  • Show a themed progress bar that fits the terminal width, plus received/total bytes and percentage during artifact downloads, followed by extraction status. Throttle non-interactive progress and preserve silent mode.

  • Add regression tests and a fix log in docs/fixes/2026-10-05-artifact-download-inactivity-timeout.md.

  • Mitigate the recurring Windows acceptance-harness runtime crash by serializing its subprocesses; add serialization/cancellation tests and a separate fix log.

why

Downloading the 312 MiB Linux artifact for #3249 could hit the overall HTTP deadline even while data was still arriving. The resulting file-write/context error obscured the download timeout, and the artifact spinner showed only the total size.

This fixes the shared PR/SHA/branch artifact path. The regular toolchain asset installer's separate 30-second timeout remains a follow-up.

validation

  • Passed focused tests with the race detector:
    go test -race ./pkg/toolchain -run 'TestDownloadPRArtifact|TestArtifactDownloadWatchdog|TestArtifactProgressReporter|TestDownloadAndInstallArtifactToDir|TestInstallArtifactBinaryToDir|TestHandlePRArtifactError|TestHandleSHAArtifactError|TestHandleRefResolveError' -count=1 -timeout=5m

  • Tests cover sustained progress beyond the idle interval, stalls before headers and mid-body, cancellation/deadlines, partial-file cleanup, stale timer callbacks, real HTTP cancellation, progress totals/throttling, silent installs, and existing token/redirect regressions.

  • ./custom-gcl run --new-from-rev=origin/main ./pkg/toolchain/...: 0 issues.

  • Changed Go files pass gofumpt; git diff --check passes. No live GitHub artifact download was performed.

  • Windows CI follow-up: semaphore regression tests pass under -race -count=10; the full acceptance harness passes under -race; Windows test cross-compilation and host/Windows lint pass. Actual Windows crash mitigation remains subject to CI.

references

Summary by CodeRabbit

  • Bug Fixes
    • Artifact downloads can continue beyond five minutes while data is arriving. Downloads that stall for five minutes are canceled, and incomplete files are removed.
    • Windows acceptance checks now run one subprocess at a time; concurrency on other platforms is unchanged.
    • Colored progress indicators display correctly in spinner messages.
  • New Features
    • Download and installation progress is displayed, including byte counts and completion status.

🤖 Automatic Updates

chore(deps): update dependency postcss-selector-parser@^6 to v7 [security] @[renovate[bot]](https://github.com/apps/renovate) (#3281) This PR contains the following updates:
Package Change Age Confidence
postcss-selector-parser@^6 ^6.1.3 → ^7.1.6 age confidence

PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion

CVE-2026-104844 / GHSA-rj75-hqrm-r3gf

More information

Details

Impact

. and # are not word delimiters in the tokenizer, so a flat selector such as
.a.a.a... reaches splitWord() as a single word token carrying n class or id
indexes. Three passes scanned those index arrays linearly for every index,
making the parse O(n^2) in the number of indexes rather than in input length:
uniqs(), the indices.forEach loop, and the Sass-interpolation filter.
Parsing a 400 KB flat selector took ~34 s on a modern laptop, fully occupying a
single thread. A benign selector of identical byte size parses in tens of
milliseconds, so the cost is driven by the index count, not the input size.
The nesting depth of such a selector is 0, so the maxNestingDepth guard added
in 7.1.3 offers no protection.

Reachability is deployment dependent. Only consumers that parse untrusted,
attacker-supplied selectors synchronously in a request path are exposed, for
example CSS sanitizers, CSS-in-JS services and online playgrounds. Ordinary
build-time use on trusted sources is not affected.

Patches

Fixed in 7.1.6. The three passes now use Set membership tests, making parsing
linear in the number of indexes. There is no behaviour change: parsing is
byte-identical on a differential corpus of 8413 selectors.

Workarounds

Cap the size of selectors accepted from untrusted sources before parsing.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

postcss/postcss-selector-parser (postcss-selector-parser@^6)

v7.1.6

Compare Source

  • fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)

v7.1.5

Compare Source

v7.1.4

Compare Source

  • fix: tolerate non-node children when serializing selectors

v7.1.3

Compare Source

  • Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)

v7.1.2

Compare Source

v7.1.1

Compare Source

  • perf: replace startsWith with strict equality (#​308)
  • fix(types): add walkUniversal declaration (#​311)

v7.1.0

Compare Source

  • feat: insert(Before|After) support multiple new node

v7.0.0

Compare Source

  • Feat: make insertions during iteration safe (major)

v6.1.4

Compare Source

  • fix: tolerate non-node children when serializing selectors

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

build(deps): bump the cicd group with 10 updates @[dependabot[bot]](https://github.com/apps/dependabot) (#3260) Bumps the cicd group with 10 updates:
Package From To
cloudposse/.github/.github/workflows/shared-release-branches.yml 0.171.0 0.173.0
github/codeql-action/upload-sarif 4.38.0 4.38.1
github/codeql-action/init 4.38.0 4.38.1
github/codeql-action/autobuild 4.38.0 4.38.1
github/codeql-action/analyze 4.38.0 4.38.1
cloudposse/.github/.github/workflows/shared-go-auto-release.yml 0.170.0 0.173.0
cloudposse/github-action-setup-atmos 3.5.0 3.6.0
codecov/codecov-action 7.0.0 7.1.1
trufflesecurity/trufflehog 3.97.4 3.97.5
aws-actions/configure-aws-credentials 6.2.4 6.3.0

Updates cloudposse/.github/.github/workflows/shared-release-branches.yml from 0.171.0 to 0.173.0

Release notes

Sourced from cloudposse/.github/.github/workflows/shared-release-branches.yml's releases.

v0.173.0

  • Add an optional deprecation_notice field that renders before Introduction in place of the Atmos tip.
  • Preserve the existing tip when no notice is supplied.

why

  • Put migration guidance near the top of deprecated action READMEs without changing notices for other projects.

references

v0.172.0

  • replace deprecated RunsOn disk presets with explicit gp3 volume settings
  • use 40 GB for default runners and 120 GB for large/xlarge runners
  • pin gp3 to the included 3,000 IOPS and 125 MiB/s baseline

The previous defaults provisioned 400 MiB/s for default/terraform runners and 750 MiB/s for large runners, creating avoidable EBS throughput charges.

Validation

  • parsed .github/runs-on.yml with YAML aliases enabled
  • confirmed no deprecated disk: runner keys remain

Expected savings: approximately $15-30/month, depending on runner volume lifetime.

Commits

Updates github/codeql-action/upload-sarif from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/upload-sarif's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/upload-sarif's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/autobuild from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/autobuild's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/autobuild's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates cloudposse/.github/.github/workflows/shared-go-auto-release.yml from 0.170.0 to 0.173.0

Release notes

Sourced from cloudposse/.github/.github/workflows/shared-go-auto-release.yml's releases.

v0.173.0

  • Add an optional deprecation_notice field that renders before Introduction in place of the Atmos tip.
  • Preserve the existing tip when no notice is supplied.

why

  • Put migration guidance near the top of deprecated action READMEs without changing notices for other projects.

references

v0.172.0

  • replace deprecated RunsOn disk presets with explicit gp3 volume settings
  • use 40 GB for default runners and 120 GB for large/xlarge runners
  • pin gp3 to the included 3,000 IOPS and 125 MiB/s baseline

The previous defaults provisioned 400 MiB/s for default/terraform runners and 750 MiB/s for large runners, creating avoidable EBS throughput charges.

Validation

  • parsed .github/runs-on.yml with YAML aliases enabled
  • confirmed no deprecated disk: runner keys remain

Expected savings: approximately $15-30/month, depending on runner volume lifetime.

v0.171.0

  • In shared-go-auto-release.yml's goreleaser job, mint a second, fresh GitHub App installation token immediately before the "Run GoReleaser" step (after all the setup/GPG-import/disk-cleanup steps), instead of reusing the single token minted at the very start of the job.
  • Use that fresh token for both the GoReleaser invocation itself and the immediately-following "Attest build provenance" step.

... (truncated)

Commits
  • 281621d feat(readme): render deprecation notices above the introduction (#283)
  • 1bce210 chore: right-size RunsOn volumes (#282)
  • 4e05ff6 fix: re-mint GitHub App token before goreleaser to avoid mid-run expiry (#281)
  • See full diff in compare view

Updates cloudposse/github-action-setup-atmos from 3.5.0 to 3.6.0

Release notes

Sourced from cloudposse/github-action-setup-atmos's releases.

v3.6.0

Move the public repository’s remaining RunsOn install job to ubuntu-latest. Standard GitHub-hosted runners are free for public repositories.

The hosted runner exposed pre-existing default-branch drift that the old RunsOn dependency cache had masked: package.json no longer matched yarn.lock, ESLint 10 was incompatible with the repository’s legacy ESLint configuration/plugins, and the checked-in dist/ bundle was stale. This PR reconciles both lockfiles, restores the compatible ESLint 8.57.1 line, and commits the reproducible Node 24 action bundle.

Validation

  • yarn --frozen-lockfile --prefer-offline
  • yarn lint:check
  • yarn format:check
  • yarn test:coverage: 63 tests pass; 96.61% line and 96.92% statement coverage
  • yarn clean && yarn build && yarn build:wrapper
  • generated dist/ verification passes
  • actionlint passes
  • no RunsOn routing labels remain in test-install.yaml

Expected savings: approximately $25–50/month.

Commits

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

Updates trufflesecurity/trufflehog from 3.97.4 to 3.97.5

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.5

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.4...v3.97.5

Commits
  • f714bf4 [SCAN-177] Purge secret parts from verification cache (#5318)
  • 4ecb5c6 Add elasticsearch source documentation (#5284)
  • 8d77a9d Add filesystem source documentation (#5285)
  • b8a71ee Add documentation for CircleCI source (#5268)
  • b1d7dae perf(engine): lowercase prefilter chunks as ASCII in a pooled buffer (#5291)
  • 07e3ac7 Introduce a new optional detector interface that will allow us to verify cred...
  • 5a6944e ci: avoid Node 20 BuildPulse action (#5266)
  • ce7b2b8 fix(detectors/ngrok): broaden valid bearer tokens matching (#5152)
  • 58bf481 Postgres: drop non-connection URI params before verifying (#5296)
  • 82fd19c Adding no-ignore flag to allow reporting of "ignored" secrets (#5297)
  • Additional commits viewable in compare view

Updates aws-actions/configure-aws-credentials from 6.2.4 to 6.3.0

Release notes

Sourced from aws-actions/configure-aws-credentials's releases.

v6.3.0

6.3.0 (2026-09-11)

Features

Changelog

Sourced from aws-actions/configure-aws-credentials's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

6.3.0 (2026-09-11)

Features

6.2.4 (2026-08-31)

Bug Fixes

  • account-ids handling, mask proxy as secret in logs (#1943) (aa65264)
  • skip backoff sleep after the final retryAndBackoff attempt (#1937) (3852440)

6.2.3 (2026-07-22)

Bug Fixes

  • attach git credentials before Tag Major Version push (#1877) (9ae780b)
  • PackedPolicyTooLarge detection in STS tags (#1899) (fa8d6a5)

6.2.2 (2026-07-07)

Miscellaneous Chores

6.2.1 (2026-06-26)

Bug Fixes

  • enforce allowed-account-ids on all auth paths (#1847) (4d281fb)

6.2.0 (2026-06-01)

Features

  • add additional session tags by default (#1775) (e0ba768)
  • add more retry logic and better logging (#1764) (540d0c1)
  • add regex validation to role-session-name (#1765) (e354499)
  • Allow custom session tags to be passed when assuming a role (#1759) (61f50f6)
  • expose run id in STS client user-agent (#1774) (29d1be3)

... (truncated)

Commits
  • e125382 chore(main): release 6.3.0 (#1963)
  • 438100a chore: add link to GH security docs (#1962)
  • e92ebcc chore: Update dist
  • 57b8365 feat: add translate-env-variables option (#1961)
  • cc49fa7 chore(docs): README main branch guidance (#1960)
  • 866cb16 chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (#1958)
  • 6782cb1 chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (#1951)
  • c20509a chore: Update dist
  • 7a41fc6 chore(deps): bump @​aws-sdk/client-sts from 3.1121.0 to 3.1127.0 (#1954)
  • 726b713 chore(deps-dev): bump @​biomejs/biome from 2.5.11 to 2.5.12 (#1957)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Don't miss a new atmos release

NewReleases is sending notifications on new releases.