From cb7a7e0c879031062b46c367aafc5d6c4f87018f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 13 May 2024 18:11:47 +0000 Subject: [PATCH] fix(deps): bump the github-actions group across 1 directory with 2 updates Bumps the github-actions group with 2 updates in the / directory: [hashicorp/setup-terraform](https://github.com/hashicorp/setup-terraform) and [hashicorp/vault-action](https://github.com/hashicorp/vault-action). Updates `hashicorp/setup-terraform` from 3.0.0 to 3.1.1 - [Release notes](https://github.com/hashicorp/setup-terraform/releases) - [Changelog](https://github.com/hashicorp/setup-terraform/blob/main/CHANGELOG.md) - [Commits](https://github.com/hashicorp/setup-terraform/compare/v3.0.0...v3.1.1) Updates `hashicorp/vault-action` from 2.7.4 to 3.0.0 - [Release notes](https://github.com/hashicorp/vault-action/releases) - [Changelog](https://github.com/hashicorp/vault-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/hashicorp/vault-action/compare/v2.7.4...v3.0.0) --- updated-dependencies: - dependency-name: hashicorp/setup-terraform dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: hashicorp/vault-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/ci.yaml | 4 ++-- .github/workflows/oidc_test.yaml | 8 ++++---- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 2a6c523..4a8d4a5 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -24,7 +24,7 @@ jobs: - uses: actions/checkout@v4 - name: Setup Terraform - uses: hashicorp/setup-terraform@v3.0.0 + uses: hashicorp/setup-terraform@v3.1.1 - name: Terraform Format id: fmt @@ -51,7 +51,7 @@ jobs: - uses: actions/checkout@v4 - name: Setup Terraform - uses: hashicorp/setup-terraform@v3.0.0 + uses: hashicorp/setup-terraform@v3.1.1 - name: Install Brew Packages # Need Bash 5 for terraform fmt in pre-commit hook diff --git a/.github/workflows/oidc_test.yaml b/.github/workflows/oidc_test.yaml index 476ccfd..104bb52 100644 --- a/.github/workflows/oidc_test.yaml +++ b/.github/workflows/oidc_test.yaml @@ -30,7 +30,7 @@ jobs: - uses: actions/checkout@v4 - name: Setup Terraform - uses: hashicorp/setup-terraform@v3.0.0 + uses: hashicorp/setup-terraform@v3.1.1 with: terraform_wrapper: false @@ -58,7 +58,7 @@ jobs: # secret path "secret/data/foo/bar". # We are unable to read "secret/data/main/secret". - name: Import Secrets - uses: hashicorp/vault-action@v2.7.4 + uses: hashicorp/vault-action@v3.0.0 id: secrets with: exportEnv: false @@ -77,7 +77,7 @@ jobs: # 'secret/data/main/secret' so this will successfully authenticate # but fail to pull the 'cdsecret' secret. - name: Attempt to read secrets outside bound OIDC policy - uses: hashicorp/vault-action@v2.7.4 + uses: hashicorp/vault-action@v3.0.0 id: failed-secrets1 continue-on-error: true with: @@ -97,7 +97,7 @@ jobs: # so it cannot be bound to a job running from another branch or a fork. # This will fail to authenticate. - name: Attempt to access another OIDC role - uses: hashicorp/vault-action@v2.7.4 + uses: hashicorp/vault-action@v3.0.0 id: failed-secrets2 continue-on-error: true with: