fix(ci): tap homebrew/core before bumping the Homebrew formula @aknysh (#3336)
## what- Tap
homebrew/corebeforebrew bump-formula-prin the release "Bump Homebrew formula" step (.github/workflows/build.yml). - Correct the step comment, which incorrectly claimed no tap was needed.
- Add a fix-log (
docs/fixes/2026-10-09-homebrew-bump-needs-core-tap.md).
why
The "Bump Homebrew formula" step fails on every release with No available formula with the name "atmos", most recently on v1.231.0 (run 37862125521). Every Homebrew bump has had to be done manually (v1.228.0, v1.229.0, v1.230.0, v1.230.1, and now v1.231.0 via homebrew-core PR #316660).
brew bump-formula-pr is a developer command that edits the formula's .rb file, so it needs homebrew/core checked out as a local tap. A fresh runner uses the formulae API with no tap, so the formula file does not exist locally and the command can't resolve atmos. Dropping HOMEBREW_NO_INSTALL_FROM_API (#3240) never fixed this because the tap was still absent either way — the earlier dry-run that appeared to prove API mode worked was run on a machine that already had homebrew/core tapped, exactly the condition CI lacks.
Verified locally: the exact CI command fails with No available formula when homebrew/core is not tapped, and resolves atmos (reaching the duplicate-PR check) once it is. brew tap homebrew/core exits 0 on current Homebrew (7.0.8) — still permitted, just no longer implicit. This step only runs on release: published, so it can't be exercised by a PR check; the next release is the first real confirmation.
references
- Supersedes the incorrect root-cause conclusion in #3240.
- Related earlier fix: #3229 (
brew shellenvPATH fix).
Summary by CodeRabbit
-
Bug Fixes
- Updated Homebrew release publishing to tap
homebrew/corebefore bumping the formula.
- Updated Homebrew release publishing to tap
-
Documentation
- Added guidance on the Homebrew tap requirement and dry-run results.
fix(ci): dedupe govulncheck SARIF stacks via ci:vulncheck mage target @osterman (#3347)
## what- Add a
ci:vulncheck <output>Mage target that runsgovulncheck -format sarif ./...and removes exact duplicate stack objects from the report before writing it. - Point the
govulncheckjob incodeql.ymlat the target instead of redirecting the scanner's output straight intogovulncheck.sarif. - The logic lives in a new
internal/ci/vulncheckpackage with unit tests; the target is listed inmagefiles/README.md. - The report replaces the output file atomically, and only after the scan succeeded and its output parsed as SARIF. A scanner failure, empty output, or malformed output fails the step and leaves any existing report untouched.
why
- Job 113647222434 finished the scan but failed the SARIF upload: results 5, 11, 12, 13 and 15 contained duplicate
stacksentries, and the SARIF schema requires that array to hold unique objects. Code scanning therefore received nothing. - Only complete duplicates are dropped. Every finding and every distinct stack (different message, different frame order) is kept, in its original position.
- It is a Mage target, not workflow shell with
jq, because the repo keeps CI logic of this size in unit-tested Go. A shell version also could not distinguish "no findings" from "scanner produced nothing", which matters when the output is uploaded to code scanning. - Coverage is 90.8% for the new package.
references
- Failing job: https://github.com/cloudposse/atmos/actions/runs/37876824022/job/113647222434
- Overlaps with #3339, which carries an earlier
jq+ shell-script version of the same fix (scripts/dedupe-sarif-stacks.jq,scripts/test-dedupe-sarif-stacks.sh, thecodeql.ymlstep, anddocs/fixes/2026-10-08-govulncheck-sarif-duplicate-stacks.md). Those pieces should be dropped from #3339 once this lands, so they do not conflict oncodeql.yml. - The full scan and the code-scanning upload only run in CI; the call-graph pass is too expensive to repeat locally. Locally verified with a stand-in
govulncheckthroughgo tool mage ci:vulncheck.
🤖 Generated with Claude Code
Summary by CodeRabbit
- Bug Fixes
- Vulnerability scan reports now remove duplicate stack entries before submission, preventing duplicate-entry errors. Reports are preserved if scanning or report processing fails.
- Chores
- Updated the vulnerability scan workflow and artifact handling to improve CI reliability.
- Documentation
- Added guidance on vulnerability scan report handling and validation.
🚀 Enhancements
fix(config): preserve imported auth identities when main config defines identities @osterman (#3339)
## what- Identities from explicit imports,
atmos.d/.atmos.dfragments, profiles, and provisioned identity files now survive when the mainatmos.yamlalso declares identities. - Source YAML is tracked per load, in effective merge order (including repeated merges), so temporary import files can be deleted and the identities still reconstructed.
- Raw identity maps are deep-merged before decoding, so a partial override keeps the imported fields, including explicit
falsevalues. Dotted names and original key casing are preserved. - If reconstruction fails to decode an identity, the previously decoded one is kept and a warning is logged.
- Regression tests assert the final
LoadConfigresult for explicit and default imports, nested imports, profiles, multiple config files, provisioned identities, dotted names, casing, YAML functions, concurrent loads, and tracker cleanup. The trace snapshot forValid Log Level in Config Filenow counts repeated source merges.
why
- Import merges ran on a temporary Viper instance that was never associated with the owning load's source tracker. Imported paths were silently omitted, and identity reconstruction then replaced the correctly merged identity map with only the main file's identities.
- Existing tests covered the individual stages, but none asserted the final
LoadConfigresult with identities split between the main file and an import.
references
- Closes #3335
- Auth fix log
- Review follow-up fix log
- The govulncheck SARIF dedupe that was originally part of this PR now lives in #3347 and is merged into this branch.
🤖 Generated with Claude Code
Summary by CodeRabbit
- Bug Fixes
- Imported authentication identities are now preserved when configuration is loaded, including identities from temporary import files.
- Identity fields merge correctly across configuration sources, preserving names and existing values when later sources provide partial overrides.
- If identity reconstruction fails, an already decoded identity remains available when possible.
fix(auth): refresh AWS user chain sessions and stabilize CI @osterman (#3351)
## what- Authenticate standalone
aws/userroots before assuming downstream roles, require unexpired session credentials for chain-cache reuse, and revalidate cached credentials before skipping authentication while preserving provider hooks, session persistence, and long-lived IAM keys. - Add generated mocks, authentication regressions, and fix logs; make include, docs-generation, and toolchain acceptance tests use local GitHub fixtures; cover Windows executable filenames; and correct CI Go-download allowlists, conditional SARIF uploads, and affected-file whitespace validation.
why
- User-to-role chains previously failed with
provider not registeredwhen sessions were missing or expired, while cached IAM keys could bypass session creation and MFA; live GitHub quotas and mismatched Windows filenames also made acceptance tests fail independently of authentication behavior. - Validation includes auth and focused race tests, unchanged CLI snapshots, a regression that reproduced the Windows filename failure before the fix, passing native Windows shard 4, lint and pre-commit checks, and 100% changed-production-line coverage measured from merged Linux CI artifacts against the 85% target.
references
Closes #3348
Summary by CodeRabbit
-
Bug Fixes
- AWS user credentials are validated before reuse in authentication chains. If cached credentials lack required session details or become invalid, authentication restarts from the chain root.
- Standalone identities can authenticate as roots in longer identity chains.
-
Tests
- Expanded coverage for authentication-chain credential handling and latest-version Terraform installation.
- Updated acceptance tests to use local mocks for GitHub-dependent data and downloads.
-
Chores
- Updated CI network policies to allow required Go downloads and skip SARIF uploads when no report is available.
fix(auth): paginate and cache SSO account name lookups @osterman (#3344)
## what- Paginate SSO account-name lookups and persist successful resolutions for one hour, isolated by SSO session, realm, region, endpoint, and account name while preserving explicit-ID precedence and credential refresh behavior.
- Add pagination/cache regression tests and a fix log covering root cause, cache behavior, and validation.
why
- Prevent false "account not found" errors beyond the first results page and repeated account listing across command invocations.
references
- Closes #3343
- Validation: Go build, full auth tests, changed-code lint, commit hooks, and website build passed; the repository-wide short test run was stopped after an unrelated
pkg/ci/startupfailure, documented in the fix log.
Summary by CodeRabbit
- Bug Fixes
- AWS SSO account-name lookups now search through all available account results, so accounts beyond the first page can be found.
- Successful account-name lookups are cached for up to one hour, reducing repeated lookups. Cache issues won’t prevent account resolution, and unsuccessful lookups aren’t cached. Changes to an account name may take up to an hour to appear.
fix(store): cache deferred atmos.Store template lookups @osterman (#3354)
## what- Cache successful, non-nil deferred
atmos.Storetemplate results per invocation, keyed by backend, lookup, and effective auth; coalesce concurrent misses. - Add regression tests for 2,200 calls over 11 keys, auth isolation, retries, and concurrent reads, plus a fix-log explaining the regression.
why
- PR #3212 moved list and describe to deferred authentication but left template store results uncached, causing repeated serialized remote reads and credential resets.
references
- Closes #3353.
Summary by CodeRabbit
- Performance
- Deferred-auth store lookups reuse successful results within an invocation, reducing repeated backend reads.
- Concurrent requests for the same store value share a single backend read.
- Reliability
- Failed lookups and nil results are not cached, allowing later requests to retry.
- Cache entries are scoped to the relevant store configuration and credentials.
🤖 Automatic Updates
build(deps): bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 @[dependabot[bot]](https://github.com/apps/dependabot) (#3146)
Bumps [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry) from 0.21.9 to 0.22.0.Release notes
Sourced from github.com/google/go-containerregistry's releases.
v0.22.0
What's Changed
- mutate: let Time and Canonical take tarball.LayerOption by
@mzihlmannin google/go-containerregistry#2403- build: add multi-architecture Cloud Build configurations for crane, gcrane, and krane by
@tprussakin google/go-containerregistry#2412- remote: resolve push-check credentials against the repository by
@mzihlmannin google/go-containerregistry#2411- Allow single-character repository paths by
@semxin google/go-containerregistry#2407- fix: add missing substitutions and workspace cleanup to new build files by
@tprussakin google/go-containerregistry#2413- remote: retry failed Puller and Pusher initialization by
@iahsanGillin google/go-containerregistry#2406- build(deps): bump the actions group across 1 directory with 8 updates by
@dependabot[bot] in google/go-containerregistry#2405- build(deps): bump the go-deps group across 1 directory with 3 updates by
@dependabot[bot] in google/go-containerregistry#2415- go.mod: bump Go version + add toolchain directive to replace .go-version file by
@Subserialin google/go-containerregistry#2416- fix: Fix new build options and provenance by
@tprussakin google/go-containerregistry#2417- fix(build): unify new build flow into cloudbuild_v2.yaml by
@tprussakin google/go-containerregistry#2419New Contributors
@mzihlmannmade their first contribution in google/go-containerregistry#2403@tprussakmade their first contribution in google/go-containerregistry#2412@semxmade their first contribution in google/go-containerregistry#2407Full Changelog: google/go-containerregistry@v0.21.9...v0.21.10
Commits
3f4ff3cfix(build): unify new build flow into cloudbuild_v2.yaml (#2419)c6b5acdfix(build): correct Cloud Build schema options and source provenance hash (#2...8f4a85dgo.mod: bump Go version + add toolchain directive to replace .go-version file...5481560build(deps): bump the go-deps group across 1 directory with 3 updates (#2415)5b5c272build(deps): bump the actions group across 1 directory with 8 updates (#2405)66dd454remote: retry failed Puller and Pusher initialization (#2406)3f47f91fix: add missing substitutions and workspace cleanup to new build files (#2413)4cb3583Allow single-character repository paths (#2407)82cc428remote: resolve push-check credentials against the repository (#2411)97815aabuild: add multi-architecture Cloud Build configurations for crane, gcrane, a...- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
chore(deps): update floci/floci docker digest to 4e451c3 @[renovate[bot]](https://github.com/apps/renovate) (#3130)
This PR contains the following updates:| Package | Type | Update | Change |
|---|---|---|---|
| floci/floci | service | digest | d2ecc80 → 4e451c3
|
Configuration
📅 Schedule: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.