feat(store): tags and expiration for Azure Key Vault store secrets @osterman (#3285)
## what- Adds
tags(string map) andexpiresoptions to the Azure Key Vault store; both are applied to every secret Atmos writes. expirestakes either a relative duration (90d,2160h, recalculated on each write) or a specific date (RFC 3339 orYYYY-MM-DD). Invalid values (e.g.0d,soon) fail when the store is created; a past fixed date is accepted with a logged warning.- Parsing lives in a new
azure_keyvault_expires.gowith table-driven tests;Get/Has/Keys/Deleteand stores that set neither option are unchanged. - Updates the stores configuration docs and the
atmos-storesagent skill, and adds a blog post and a Secrets Management roadmap milestone.
why
- Organizations that enforce an Azure Policy requiring tags and an expiration date on every Key Vault secret could not use Azure Key Vault as an Atmos store, because Atmos wrote only the secret value and the policy rejected the write.
- A single
expiresfield accepting a duration or a date avoids two overlapping options, and the relative form never goes stale the way a fixed date eventually does.
references
- closes #1549
Summary by CodeRabbit
- New Features
- Azure Key Vault secrets can include configured tags and expiration when written. Expiration accepts durations of at least one second, RFC 3339 timestamps, and dates; relative durations are recalculated on each write.
- Invalid expiration values are rejected when the store is created. Past fixed expiration dates are accepted with a warning.
- Bug Fixes
- Signature verification retries a specific Windows socket-access failure; other permission errors remain non-retryable.
- Documentation
- Added Azure Key Vault configuration guidance and updated links to YAML function documentation.
- Documented the Windows signature-verification retry behavior.
feat(backend): add bucket_namespace option for S3 state bucket provisioning @osterman (#3288)
## what- Add an optional
provision.backend.bucket_namespacesetting. The S3 backend provisioner sends it as theBucketNamespaceparameter of the S3CreateBucketcall when it creates a state bucket. - Validate the value against the namespaces the AWS SDK defines (read from the SDK enum, so Atmos keeps no list of its own) before any AWS call is made. A non-string value is rejected earlier with its own error.
- Read the option from
provision.backend, so it never appears in the generated Terraform backend config. Other backend types ignore it at runtime, and omitting it leaves existing behavior unchanged. - Scope the manifest schema to Terraform components: the setting lives in a new terraform-only
terraform_provisiondefinition, and manifest validation rejects it whenbackend_typeis set to anything other thans3(an unset or!includedbackend_typeis not checked). - Add docs, a changelog post, a roadmap milestone, and tests. Also fix a broken Docusaurus anchor in
scaffold validatethat the website build reported.
why
- Amazon S3 offers an account-scoped bucket namespace that reserves bucket names to the owning account, avoiding name collisions and name reuse after deletion. It is selected by a parameter on the creation request, which Atmos never sent, so teams that want it had to bootstrap state buckets outside Atmos.
- Passing the value through, with validation against the SDK's own values, keeps Atmos free of any naming convention or account/region assumptions.
- The shared
provisionschema definition also feeds Kubernetes, Helm, and other component types, so the S3-only setting needed its own terraform-scoped definition.
references
🤖 Generated with Claude Code
Summary by CodeRabbit
- New Features
- Added optional S3 backend bucket namespace configuration. Set it to
globaloraccount-regionalto control the namespace used when Atmos creates a bucket; leaving it unset preserves existing behavior. The setting applies only to S3 and is not included in generated Terraform backend configuration.
- Added optional S3 backend bucket namespace configuration. Set it to
- Bug Fixes
- Invalid namespace types and unsupported values are now rejected with clear errors before AWS requests are made.
- Documentation
- Added guidance on configuring bucket namespaces and updated a scaffold documentation link.
fix(docs): preserve sidebar context and explain component/workflow names @osterman (#3291)
## what- Preserve clicked sidebar entries, expanded branches, and scroll position across shared links, cross-section return trails, browser Back/Forward, filtering, and mobile navigation while keeping All reference available.
- Link component and workflow
<name>categories and overview pages to naming guides covering YAML keys, CLI usage, dependencies, implementation paths, scope, and file disambiguation, and improve active-link contrast in dark mode.
why
- Keep Workflows → Steps → Back anchored to the original article and Terraform →
<name>→ dependencies/retry anchored to the clicked branch, while making placeholder names understandable without changing canonical URLs, breadcrumbs, schemas, or runtime naming rules.
references
- Validation: 56 navigation tests passing (including early hydration toggles and consecutive expansion updates); naming examples validated against the manifest schema; agent-browser desktop/mobile, history, filtering, keyboard, and new-tab checks passed; sidebar accessibility audit reported zero violations; documentation build passed with release-history scans skipped and an existing unrelated scaffold-anchor warning.
Summary by CodeRabbit
-
Documentation
- Added guidance on naming workflow and component instances, including how names are used in commands, dependencies, and implementation paths.
- Added links to naming guidance from the relevant workflow and component navigation pages.
-
New Features
- Sidebar navigation now includes Back and All controls, remembers navigation and scroll position, and restores the selected section when navigating through browser history.
- Sidebar categories link to their documentation, and search filtering retains matching navigation items.
fix(website): unblock prod deploy; build website in merge queue @osterman (#3287)
## what- Add
related_docsfront matter toexamples/scaffolding-yaml-functions/README.md(links toscaffold generate,scaffold validate, and the!includefunction). - Add a
merge_grouptrigger toWebsite Preview Buildso the website prebuild tests and the Docusaurus build also run against the synthetic merge-queue commit. The preview deploy still ignores these runs because they have no associated PR number.
why
- The
Website Deploy Prodrun forbd75d3bc88failed in the build step, so atmos.tools has been stale since #3195 (last good deploy). Theexample-docsprebuild test added in #3272 requires every example README to declare at least tworelated_docs, and the example added in #3230 had none. Each PR passed on its own; they only conflict once combined. - The merge queue only runs CodeQL, Tests, Validate Codeowners, and Verify Symlinks. The website build was
pull_request-only, so nothing validated the combined result before it reachedmain. Theconcurrencyblock on the deploy workflow only serializes deploys; it does not validate content. - To make the new job block merges, add it as a required check in the
Merge Queueruleset. That is a repo setting and is not changed here.
references
- Failing run: https://github.com/cloudposse/atmos/actions/runs/37501347880
- Introduced by #3230 (example) and #3272 (prebuild test)
Summary by CodeRabbit
- Chores
- Website preview builds now also run for merge-queue checks.
- Documentation
- Added links to documentation for scaffold generation, template configuration, scaffold validation, and the
!includeYAML function.
- Added links to documentation for scaffold generation, template configuration, scaffold validation, and the
docs: improve navigation, command intros, and example guides @osterman (#3272)
## what- Align Stack Configuration with supported YAML scopes, canonical references, status dots, component-library navigation and overviews generated from reusable sidebar_group front matter, and YAML-shaped workflow navigation; reorganize Reference around CLI essentials, capabilities, configuration, automation, and resources, with prominent CI/CD navigation and dedicated GitHub Actions guides.
- Improve Learn navigation, tutorial callouts, all command introductions, the container overview, sidebar filtering and spacing, and terminal rendering; use front-matter references and inline documentation links across all 72 examples, unwrap the GitOps demo into built-in commands, and isolate AI toolchain tests from public registries.
why
- Make commands and CI workflows easier to find, explain configuration scopes and feature use cases, and preserve existing public URLs and historical CI anchors.
references
- Validation: 38 navigation tests, Intro coverage across all 369 command pages, example link coverage and GitOps recording validation, 29 terminal regression tests, production website build, commit hooks, desktop/mobile browser checks, and AI toolchain tests with network access blocked.
feat(scaffold): !include and other YAML functions in scaffold.yaml @jorrite (#3230)
## whatscaffold.yamlnow resolves a shared set of Atmos YAML functions, not just!include:!include/!include.raw,!env,!random,!cwd, the!git.*/!repo-rootfamily, and!literal— anywhere a scaffold manifest currently accepts a literal value:options:, atype: computedfield'svalue:, or amatrix:axis.- Resolution happens via one shared, policy-driven tag walker (
pkg/utils.WalkYAMLTags/TagWalkPolicy) that both the stack-manifest loader and scaffold's ownScaffoldTagPolicygo through — not a bespoke, scaffold-only walker. - Any tag that needs real stack/component/backend context (
!terraform.state,!store,!secret, etc.) is rejected outright with a clear error naming it, instead of silently deferred to a later phasescaffold.yamlhas none of. - A locally-included file is excluded from generated output automatically, the same way
scaffold.yamlitself is. atmos scaffold validateresolves all of this too, not justgenerate, so a missing file, bad filter, or malformed function call is caught before anyone runsgenerate.- Docs (
generate.mdx), blog post, roadmap entry, and example (examples/scaffolding-yaml-functions, renamed fromscaffolding-include) updated to demonstrate!includeplus!git.branchand!env.
why
- Small pieces of reference data (license choices, region codes, a naming-convention lookup table) show up constantly in real scaffold templates and rarely stay confined to one field — until now, that table had nowhere to live but inside
scaffold.yamlitself, copied into every field that needed it.!includealready solves this for stack manifests; extending it to scaffold manifests reuses a mechanism users already know. - The original implementation added a bespoke
!include-only tag walker, duplicating the stack-manifest loader's own dispatch logic. Refactored into one shared walker instead, so supporting more of Atmos's YAML function catalog didn't mean reinventing dispatch a third time.
A note on !exec
An earlier version of this PR included !exec in the expanded tag set. A field-test pass against the real binary found that was a real RCE risk, not a theoretical one: scaffold.yaml is resolved for every configured template just to show its name/description in atmos scaffold list and the interactive template picker — not only the one a user actually selects or generates. With !exec supported, simply running atmos scaffold list would silently execute a shell command from any configured template, including a shared or vendored one, with no generate, --force, or confirmation involved (confirmed live with a working touch-based proof-of-execution). !exec is removed entirely as a result; every other context-free tag is unaffected.
Fixes found during review
- An embedded (built-in) template's local
!includetarget could resolve relative to the process's CWD instead of failing cleanly, since the internal"embedded"marker was passed around as if it were a real directory. - A remote-fetched template's (
oci://,git::,https://,s3://) local!includealways failed generation: the real fetch directory gets overwritten with the original remote reference string right after fetching (for display/provenance), and a later re-parse of the samescaffold.yamlwas using that overwritten value instead of the real, still-alive directory. - A transitively-included file's own
!includetag was confirmed unreachable:!include's fetch decodes the included file's content generically, and a custom YAML tag doesn't survive that decode. Documented the actual (pre-existing, shared with stack manifests) limitation rather than "fixing" something that was never reachable -- and, per a later review pass, added that same explanation to the user-facing docs (generate.mdx), not just the internal doc comment.
references
- Follow-up to #3222 (
type: computedfields), which this PR builds on and which merged ase42695003. - Docs:
generate.mdx#loading-external-data-with-include-and-other-yaml-functions - Blog post:
website/blog/2026-10-01-scaffold-include.mdx - Example:
examples/scaffolding-yaml-functions
Summary by CodeRabbit
- New Features
- Scaffold templates resolve supported YAML functions—including includes, environment and Git values, random values, working-directory values, and literals—before schema validation.
- Included local files can provide options, computed values, and matrix axes without being copied into generated projects. Includes in fetched remote templates resolve relative to the fetched template.
- Scaffold validation resolves includes and reports missing sources or values that fail schema validation. Functions requiring stack, component, or backend context, as well as
!exec, are unsupported.
- Performance
- Large text changes are processed more efficiently during generation.
- Documentation
- Added guidance and an example covering YAML functions in scaffold templates.
🚀 Enhancements
fix: tailor upgrade hints to the Atmos installation method @osterman (#3293)
## what- Tailor Atmos upgrade notices to the detected installation method, with a separate implementation per installer in
pkg/installerand rendering inpkg/upgrade, replacing the utils helper. - Add detection, timeout, structured-output, and stderr snapshot tests plus documentation while preserving update-check timing and stdout behavior.
why
- The existing notice always suggested Atmos's native installer, which could create a second installation; manager-specific guidance now respects version pins, treats DEB/RPM/APK repository availability as conditional, and falls back to installation documentation when ownership is unknown.
references
- Version-check documentation
- Validation: focused version-command tests, race-enabled installer/renderer tests, Windows/Linux cross-compilation,
atmos lint --changed, and the website production build; installer coverage 93.4%, renderer coverage 100%.
Summary by CodeRabbit
- New Features
- Update notices now show installation-specific upgrade guidance, including package-manager commands, version-manager steps, or a releases-page link.
- Atmos detects common package-manager, version-manager, and native toolchain installations using read-only checks with a short time limit.
- Installation-specific guidance appears in automatic notices and
atmos version --check. JSON and YAML output remain free of notices.
- Documentation
- Added information about upgrade notices, supported installation types, and detection behavior.
fix(git): keep-history init no longer requires branch in source @bonddim (#3255)
## what- With
init.keep_history: true,atmos git initnow clonesinit.fromat its default branch, then creates the configuredbranchwithgit checkout -B. The configuredbranchno longer has to exist in the source repository. - Corrected the
atmos git initdocs, which said the branch had to exist in the source.
why
- In keep-history mode, Atmos ran
git clone --branch <branch>againstinit.fromusing the destination repository'sbranch. That branch belongs to the target repo, so the clone failed withfatal: Remote branch init not found in upstream origin. keep_history: falsealready treatsbranchas the name of the new history. Keep-history mode now does the same, while still preserving the source history and keeping the source as theupstreamremote.
Behavior change: if the configured branch also existed in the source (e.g. both use develop), keep-history init used to seed from that branch. It now seeds from the source's default branch.
references
- closes #3254
🤖 Generated with Claude Code
Summary by CodeRabbit
-
Git Initialization
- Seeding now starts from the source repository’s default branch in both history modes.
- In keep-history mode, the configured destination branch is created or reset at the cloned commit, so it no longer needs to exist in the source repository.
- Fresh-history mode continues to use a shallow clone.
-
Documentation
- Updated the
git initguide to reflect how keep-history mode handles the configured branch.
- Updated the
fix(scaffold): stop leaking internal gitref-probe step name into spinner @jorrite (#3279)
## Whatatmos scaffold generate briefly showed an internal step identifier in its spinner text when fetching a //subdir git source:
⣻ Fetching scaffold template `gitref-probe` ...
resolveSubdirGitRef (in pkg/generator/source/resolver.go) does a throwaway probe fetch into a temp directory purely to pre-resolve the commit for a //subdir git source before the real content fetch runs (see pinSubdirGitSource's doc comment). That probe fetch passed the internal literal "gitref-probe" as the spinner's displayed template name instead of the actual template name.
Why
The literal "gitref-probe" is an internal identifier for the probe step, not something a user should ever see. It leaked into user-facing spinner output.
Fix
Thread the real template name through pinSubdirGitSource → resolveSubdirGitRef → fetchRemoteSource, so the probe fetch's spinner shows the same user-facing label (Fetching scaffold template `<name>`) as the real content fetch that follows it, instead of the internal step name.
Scope check: grepped the rest of the scaffold generate path (pkg/generator/) for other spinner/progress messages — resolver.go's fetchRemoteSource is the only one, and it's now fixed. No other instance of this class of bug was found in that path.
References
pkg/generator/source/resolver.godocs/fixes/2026-10-06-scaffold-gitref-probe-spinner-label.md
Test plan
-
go build ./... -
go vet ./pkg/generator/... - Updated the three existing unit tests that call
pinSubdirGitSource/resolveSubdirGitRefdirectly to pass a template name - Manually ran
atmos scaffold generateagainst a localgit:://subdirsource and confirmed the spinner no longer showsgitref-probe— it now shows the real source/name on both the probe and content fetch
🤖 Generated with Claude Code
Summary by CodeRabbit
- Bug Fixes
- Git-based template generation now displays the template name consistently during both the preliminary check and content fetch, instead of showing “gitref-probe.”
fix(agent-skills): track the Claude Code plugin version via Version Tracker @osterman (#3195)
## what- Track
cloudposse/atmos's own latest release as a Version Tracker dependency (version.dependencies.atmosinatmos.yaml, locked inversions.lock.yaml). - Write that version into
agent-skills/.claude-plugin/plugin.jsonand.claude-plugin/marketplace.json(top-level and theatmosplugin entry, which had noversionbefore) using thejsonfile manager, withformat: '{{ trimPrefix "v" .Version }}'so the manifests carry bare semver. - Backfill both manifests from
1.0.0to the current release. - Add a
plugin-versionjob to.github/workflows/build.yml(needs: docker) that runsatmos version track updateandapplyinside the image thedockerjob just pushed, then opens ano-releasePR with the refreshed manifests and lock file. It replaced an earlier standaloneregistry_package-triggered workflow (removed): that trigger would likely never have fired, since the image is pushed with the defaultGITHUB_TOKENand GitHub doesn't start workflow runs from events that token causes. - Remediate 3 Dependabot alerts found after pushing:
containerd/containerd/v2(#299, medium — OCI index graph amplification DoS),fast-uri(#300/#301, high — authority injection / host confusion),image-size(#297/#298, high — parser DoS). All patch/minor bumps within their existing major version.
why
plugin.jsondeclared"version": "1.0.0"at every commit since it was added, andclaude plugin updatecompares declared versions, so installed plugins could never pick up new skills. Installs from months ago still serve the original 21 skills whileagent-skills/skills/now has 52.- Claude Code's plugin cache is version-scoped, so a version bump is what triggers a fresh copy of the skills.
- Version Tracker (the
jsonmanager andformatfield, both added upstream in Atmos itself while this PR was in progress) replaces the shell-and-sedapproach this started as: no template/rendered file pairs, and the manifests stay single-source files. - The security fixes were opportunistic, triggered by GitHub's Dependabot scan of this branch's push.
references
- closes #2895
- Version Tracker fixes this depended on: #2900 (draft releases excluded from resolution), #2966 (
jsonmanager, explicit emptyversion.files), #3069 (formatonsetentries) — all landed upstream in Atmos itself during this PR - Dependabot alerts remediated: #297, #298, #299, #300, #301
🤖 Generated with Claude Code
Summary by CodeRabbit
- Updates
- The Atmos Claude Code plugin and its marketplace listing now report version 1.229.0, matching the Atmos release.
- Plugin version information is refreshed automatically following stable Atmos releases.
fix(toolchain): time out artifact downloads only when stalled @osterman (#3277)
## what-
Replace the five-minute total deadline for PR/SHA/branch artifact downloads with an inactivity watchdog that resets on response headers and received bytes. Active transfers can continue beyond five minutes; caller deadlines still apply.
-
Report
artifact download timed out: no download progress for 5m, clean up partial files after closing them, and retain redirect authentication protections. -
Show a themed progress bar that fits the terminal width, plus received/total bytes and percentage during artifact downloads, followed by extraction status. Throttle non-interactive progress and preserve silent mode.
-
Add regression tests and a fix log in
docs/fixes/2026-10-05-artifact-download-inactivity-timeout.md. -
Mitigate the recurring Windows acceptance-harness runtime crash by serializing its subprocesses; add serialization/cancellation tests and a separate fix log.
why
Downloading the 312 MiB Linux artifact for #3249 could hit the overall HTTP deadline even while data was still arriving. The resulting file-write/context error obscured the download timeout, and the artifact spinner showed only the total size.
This fixes the shared PR/SHA/branch artifact path. The regular toolchain asset installer's separate 30-second timeout remains a follow-up.
validation
-
Passed focused tests with the race detector:
go test -race ./pkg/toolchain -run 'TestDownloadPRArtifact|TestArtifactDownloadWatchdog|TestArtifactProgressReporter|TestDownloadAndInstallArtifactToDir|TestInstallArtifactBinaryToDir|TestHandlePRArtifactError|TestHandleSHAArtifactError|TestHandleRefResolveError' -count=1 -timeout=5m -
Tests cover sustained progress beyond the idle interval, stalls before headers and mid-body, cancellation/deadlines, partial-file cleanup, stale timer callbacks, real HTTP cancellation, progress totals/throttling, silent installs, and existing token/redirect regressions.
-
./custom-gcl run --new-from-rev=origin/main ./pkg/toolchain/...: 0 issues. -
Changed Go files pass
gofumpt;git diff --checkpasses. No live GitHub artifact download was performed. -
Windows CI follow-up: semaphore regression tests pass under
-race -count=10; the full acceptance harness passes under-race; Windows test cross-compilation and host/Windows lint pass. Actual Windows crash mitigation remains subject to CI.
references
Summary by CodeRabbit
- Bug Fixes
- Artifact downloads can continue beyond five minutes while data is arriving. Downloads that stall for five minutes are canceled, and incomplete files are removed.
- Windows acceptance checks now run one subprocess at a time; concurrency on other platforms is unchanged.
- Colored progress indicators display correctly in spinner messages.
- New Features
- Download and installation progress is displayed, including byte counts and completion status.
🤖 Automatic Updates
chore(deps): update dependency postcss-selector-parser@^6 to v7 [security] @[renovate[bot]](https://github.com/apps/renovate) (#3281)
This PR contains the following updates:| Package | Change | Age | Confidence |
|---|---|---|---|
| postcss-selector-parser@^6 | ^6.1.3 → ^7.1.6
|
PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion
CVE-2026-104844 / GHSA-rj75-hqrm-r3gf
Reachability is deployment dependent. Only consumers that parse untrusted, Fixed in 7.1.6. The three passes now use Set membership tests, making parsing Cap the size of selectors accepted from untrusted sources before parsing.
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
More information
Details
Impact
. and # are not word delimiters in the tokenizer, so a flat selector such as
.a.a.a... reaches splitWord() as a single word token carrying n class or id
indexes. Three passes scanned those index arrays linearly for every index,
making the parse O(n^2) in the number of indexes rather than in input length:
uniqs(), the indices.forEach loop, and the Sass-interpolation filter.
Parsing a 400 KB flat selector took ~34 s on a modern laptop, fully occupying a
single thread. A benign selector of identical byte size parses in tens of
milliseconds, so the cost is driven by the index count, not the input size.
The nesting depth of such a selector is 0, so the maxNestingDepth guard added
in 7.1.3 offers no protection.
attacker-supplied selectors synchronously in a request path are exposed, for
example CSS sanitizers, CSS-in-JS services and online playgrounds. Ordinary
build-time use on trusted sources is not affected.
Patches
linear in the number of indexes. There is no behaviour change: parsing is
byte-identical on a differential corpus of 8413 selectors.
Workarounds
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Release Notes
postcss/postcss-selector-parser (postcss-selector-parser@^6)
v7.1.6
- fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)
v7.1.5
- fix: don't treat a non-prefix token before
|as a namespace (#324 by @spokodev) - fix: preserve whitespace before a
*namespace in attribute selectors (#325 by @spokodev) - fix: TypeError on unclosed
[,(and trailing|(#330 by @theRizwan)
v7.1.4
- fix: tolerate non-node children when serializing selectors
v7.1.3
- Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)
v7.1.2
- Fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (#316 by @MoOx)
v7.1.1
- perf: replace startsWith with strict equality (#308)
- fix(types): add walkUniversal declaration (#311)
v7.1.0
- feat: insert(Before|After) support multiple new node
v7.0.0
- Feat: make insertions during iteration safe (major)
v6.1.4
- fix: tolerate non-node children when serializing selectors
Configuration
📅 Schedule: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.
build(deps): bump the cicd group with 10 updates @[dependabot[bot]](https://github.com/apps/dependabot) (#3260)
Bumps the cicd group with 10 updates:| Package | From | To |
|---|---|---|
| cloudposse/.github/.github/workflows/shared-release-branches.yml | 0.171.0
| 0.173.0
|
| github/codeql-action/upload-sarif | 4.38.0
| 4.38.1
|
| github/codeql-action/init | 4.38.0
| 4.38.1
|
| github/codeql-action/autobuild | 4.38.0
| 4.38.1
|
| github/codeql-action/analyze | 4.38.0
| 4.38.1
|
| cloudposse/.github/.github/workflows/shared-go-auto-release.yml | 0.170.0
| 0.173.0
|
| cloudposse/github-action-setup-atmos | 3.5.0
| 3.6.0
|
| codecov/codecov-action | 7.0.0
| 7.1.1
|
| trufflesecurity/trufflehog | 3.97.4
| 3.97.5
|
| aws-actions/configure-aws-credentials | 6.2.4
| 6.3.0
|
Updates Sourced from cloudposse/.github/.github/workflows/shared-release-branches.yml's releases.
The previous defaults provisioned 400 MiB/s for default/terraform runners and 750 MiB/s for large runners, creating avoidable EBS throughput charges.
Expected savings: approximately $15-30/month, depending on runner volume lifetime.
cloudposse/.github/.github/workflows/shared-release-branches.yml from 0.171.0 to 0.173.0
Release notes
v0.173.0
deprecation_notice field that renders before Introduction in place of the Atmos tip.
why
references
v0.172.0
disk presets with explicit gp3 volume settings
Validation
.github/runs-on.yml with YAML aliases enabled
disk: runner keys remain
Commits
281621d feat(readme): render deprecation notices above the introduction (#283)
1bce210 chore: right-size RunsOn volumes (#282)
Updates Sourced from github/codeql-action/upload-sarif's releases.
Sourced from github/codeql-action/upload-sarif's changelog.
See the releases page for the relevant changes to the CodeQL CLI and language packs.
No user facing changes.
No user facing changes.
No user facing changes.
... (truncated)
github/codeql-action/upload-sarif from 4.38.0 to 4.38.1
Release notes
v4.38.1
Changelog
CodeQL Action Changelog
[UNRELEASED]
4.38.2 - 24 Sept 2026
4.38.1 - 18 Sept 2026
4.38.0 - 09 Sept 2026
linux-arm64 CodeQL bundle when available. #4072
4.37.9 - 26 Aug 2026
4.37.8 - 21 Aug 2026
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
.github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
init Action instead of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
4.37.3 - 22 Jul 2026
Commits
1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
a97cdca Add changelog entry for #4146
cc6c691 Update changelog for v4.38.1
a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
07fa87d Clarify the latest-nightly eligibility exception
f18f353 Describe the bundle URL resolver
ecec9b5 Share per-language telemetry fields without renaming
79fe3a1 Move download telemetry into the status-report directory
ead1f7d Rename the platform module
549d498 Simplify per-language platform eligibility checks
Updates Sourced from github/codeql-action/init's releases.
Sourced from github/codeql-action/init's changelog.
See the releases page for the relevant changes to the CodeQL CLI and language packs.
No user facing changes.
No user facing changes.
No user facing changes.
... (truncated)
github/codeql-action/init from 4.38.0 to 4.38.1
Release notes
v4.38.1
Changelog
CodeQL Action Changelog
[UNRELEASED]
4.38.2 - 24 Sept 2026
4.38.1 - 18 Sept 2026
4.38.0 - 09 Sept 2026
linux-arm64 CodeQL bundle when available. #4072
4.37.9 - 26 Aug 2026
4.37.8 - 21 Aug 2026
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
.github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
init Action instead of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
4.37.3 - 22 Jul 2026
Commits
1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
a97cdca Add changelog entry for #4146
cc6c691 Update changelog for v4.38.1
a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
07fa87d Clarify the latest-nightly eligibility exception
f18f353 Describe the bundle URL resolver
ecec9b5 Share per-language telemetry fields without renaming
79fe3a1 Move download telemetry into the status-report directory
ead1f7d Rename the platform module
549d498 Simplify per-language platform eligibility checks
Updates Sourced from github/codeql-action/autobuild's releases.
Sourced from github/codeql-action/autobuild's changelog.
See the releases page for the relevant changes to the CodeQL CLI and language packs.
No user facing changes.
No user facing changes.
No user facing changes.
... (truncated)
github/codeql-action/autobuild from 4.38.0 to 4.38.1
Release notes
v4.38.1
Changelog
CodeQL Action Changelog
[UNRELEASED]
4.38.2 - 24 Sept 2026
4.38.1 - 18 Sept 2026
4.38.0 - 09 Sept 2026
linux-arm64 CodeQL bundle when available. #4072
4.37.9 - 26 Aug 2026
4.37.8 - 21 Aug 2026
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
.github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
init Action instead of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
4.37.3 - 22 Jul 2026
Commits
1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
a97cdca Add changelog entry for #4146
cc6c691 Update changelog for v4.38.1
a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
07fa87d Clarify the latest-nightly eligibility exception
f18f353 Describe the bundle URL resolver
ecec9b5 Share per-language telemetry fields without renaming
79fe3a1 Move download telemetry into the status-report directory
ead1f7d Rename the platform module
549d498 Simplify per-language platform eligibility checks
Updates Sourced from github/codeql-action/analyze's releases.
Sourced from github/codeql-action/analyze's changelog.
See the releases page for the relevant changes to the CodeQL CLI and language packs.
No user facing changes.
No user facing changes.
No user facing changes.
... (truncated)
github/codeql-action/analyze from 4.38.0 to 4.38.1
Release notes
v4.38.1
Changelog
CodeQL Action Changelog
[UNRELEASED]
4.38.2 - 24 Sept 2026
4.38.1 - 18 Sept 2026
4.38.0 - 09 Sept 2026
linux-arm64 CodeQL bundle when available. #4072
4.37.9 - 26 Aug 2026
4.37.8 - 21 Aug 2026
4.37.7 - 13 Aug 2026
4.37.6 - 04 Aug 2026
.github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070
4.37.5 - 03 Aug 2026
init Action instead of falling back to downloading the bundle before extracting it. #4061
4.37.4 - 29 Jul 2026
tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
4.37.3 - 22 Jul 2026
Commits
1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
a97cdca Add changelog entry for #4146
cc6c691 Update changelog for v4.38.1
a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
07fa87d Clarify the latest-nightly eligibility exception
f18f353 Describe the bundle URL resolver
ecec9b5 Share per-language telemetry fields without renaming
79fe3a1 Move download telemetry into the status-report directory
ead1f7d Rename the platform module
549d498 Simplify per-language platform eligibility checks
Updates Sourced from cloudposse/.github/.github/workflows/shared-go-auto-release.yml's releases.
The previous defaults provisioned 400 MiB/s for default/terraform runners and 750 MiB/s for large runners, creating avoidable EBS throughput charges.
Expected savings: approximately $15-30/month, depending on runner volume lifetime.
... (truncated)
cloudposse/.github/.github/workflows/shared-go-auto-release.yml from 0.170.0 to 0.173.0
Release notes
v0.173.0
deprecation_notice field that renders before Introduction in place of the Atmos tip.
why
references
v0.172.0
disk presets with explicit gp3 volume settings
Validation
.github/runs-on.yml with YAML aliases enabled
disk: runner keys remain
v0.171.0
shared-go-auto-release.yml's goreleaser job, mint a second, fresh
GitHub App installation token immediately before the "Run GoReleaser" step
(after all the setup/GPG-import/disk-cleanup steps), instead of reusing the
single token minted at the very start of the job.
Commits
Updates Sourced from cloudposse/github-action-setup-atmos's releases.
Move the public repository’s remaining RunsOn install job to The hosted runner exposed pre-existing default-branch drift that the old RunsOn dependency cache had masked: Expected savings: approximately $25–50/month.
cloudposse/github-action-setup-atmos from 3.5.0 to 3.6.0
Release notes
v3.6.0
ubuntu-latest. Standard GitHub-hosted runners are free for public repositories.
package.json no longer matched yarn.lock, ESLint 10 was incompatible with the repository’s legacy ESLint configuration/plugins, and the checked-in dist/ bundle was stale. This PR reconciles both lockfiles, restores the compatible ESLint 8.57.1 line, and commits the reproducible Node 24 action bundle.
Validation
yarn --frozen-lockfile --prefer-offline
yarn lint:check
yarn format:check
yarn test:coverage: 63 tests pass; 96.61% line and 96.92% statement coverage
yarn clean && yarn build && yarn build:wrapper
dist/ verification passes
test-install.yaml
Commits
9e8d1e2 ci: use free hosted runner for install tests (#121)
Updates Sourced from codecov/codecov-action's releases.
Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1
Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0
codecov/codecov-action from 7.0.0 to 7.1.1
Release notes
v7.1.1
What's Changed
@thomasrockhu-codecov in codecov/codecov-action#1973
v7.1.0
What's Changed
@thomasrockhu-codecov in codecov/codecov-action#1971
Commits
303a32d chore(release): 7.1.1 (#1973)
0b35c9e chore(release): 7.1.0 (#1971)
Updates Sourced from trufflesecurity/trufflehog's releases.
Full Changelog: trufflesecurity/trufflehog@v3.97.4...v3.97.5
trufflesecurity/trufflehog from 3.97.4 to 3.97.5
Release notes
v3.97.5
What's Changed
@renovate[bot] in trufflesecurity/trufflehog#5274
@renovate[bot] in trufflesecurity/trufflehog#5250
@renovate[bot] in trufflesecurity/trufflehog#5251
@kashifkhan0771 in trufflesecurity/trufflehog#5275
@unsmith in trufflesecurity/trufflehog#5258
@shahzadhaider1 in trufflesecurity/trufflehog#5286
@mwoss in trufflesecurity/trufflehog#5103
@bradlarsen in trufflesecurity/trufflehog#5273
@mariduv in trufflesecurity/trufflehog#5257
@jordanTunstill in trufflesecurity/trufflehog#5297
@jordanTunstill in trufflesecurity/trufflehog#5296
@mattbrady-1 in trufflesecurity/trufflehog#5152
@dustin-decker in trufflesecurity/trufflehog#5266
@kvnphvm in trufflesecurity/trufflehog#5298
@kashifkhan0771 in trufflesecurity/trufflehog#5291
@kashifkhan0771 in trufflesecurity/trufflehog#5268
@kashifkhan0771 in trufflesecurity/trufflehog#5285
@kashifkhan0771 in trufflesecurity/trufflehog#5284
@casey-tran in trufflesecurity/trufflehog#5318
New Contributors
@mwoss made their first contribution in trufflesecurity/trufflehog#5103
@kvnphvm made their first contribution in trufflesecurity/trufflehog#5298
Commits
f714bf4 [SCAN-177] Purge secret parts from verification cache (#5318)
4ecb5c6 Add elasticsearch source documentation (#5284)
8d77a9d Add filesystem source documentation (#5285)
b8a71ee Add documentation for CircleCI source (#5268)
b1d7dae perf(engine): lowercase prefilter chunks as ASCII in a pooled buffer (#5291)
07e3ac7 Introduce a new optional detector interface that will allow us to verify cred...
5a6944e ci: avoid Node 20 BuildPulse action (#5266)
ce7b2b8 fix(detectors/ngrok): broaden valid bearer tokens matching (#5152)
58bf481 Postgres: drop non-connection URI params before verifying (#5296)
82fd19c Adding no-ignore flag to allow reporting of "ignored" secrets (#5297)
Updates Sourced from aws-actions/configure-aws-credentials's releases.
Sourced from aws-actions/configure-aws-credentials's changelog.
All notable changes to this project will be documented in this file. See standard-version for commit guidelines.
... (truncated)
aws-actions/configure-aws-credentials from 6.2.4 to 6.3.0
Release notes
v6.3.0
6.3.0 (2026-09-11)
Features
Changelog
Changelog
6.3.0 (2026-09-11)
Features
6.2.4 (2026-08-31)
Bug Fixes
6.2.3 (2026-07-22)
Bug Fixes
6.2.2 (2026-07-07)
Miscellaneous Chores
6.2.1 (2026-06-26)
Bug Fixes
6.2.0 (2026-06-01)
Features
Commits
e125382 chore(main): release 6.3.0 (#1963)
438100a chore: add link to GH security docs (#1962)
e92ebcc chore: Update dist
57b8365 feat: add translate-env-variables option (#1961)
cc49fa7 chore(docs): README main branch guidance (#1960)
866cb16 chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (#1958)
6782cb1 chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (#1951)
c20509a chore: Update dist
7a41fc6 chore(deps): bump @aws-sdk/client-sts from 3.1121.0 to 3.1127.0 (#1954)
726b713 chore(deps-dev): bump @biomejs/biome from 2.5.11 to 2.5.12 (#1957)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions