Tom Keller
58e7c47adf
fix: skip credential check on output-env-credentials: false ( #1778 )
...
Closes #1554 .
2026-05-14 13:39:34 -07:00
Tom Keller
f35a7d7d7e
chore: document forgejo compatibility ( #1776 )
...
* chore: document forgejo compatibility
* chore: linting fixes
2026-05-13 15:49:18 -07:00
Tom Keller
e0ba768507
feat: add additional session tags by default ( #1775 )
...
Closes #390 .
Note that 50 session tags are the AWS default, and this commit changes
our default set from 7 tags to 15 tags. This commit includes logic to
split the tags into "required" vs "overridable". Required tags are this
action's previous defaults and could never be overridden. Overridable
tags are the new set and can be overridden by custom-tags. The action
will not add tags if the addition plus the required plus the user's
custom tags exceed the AWS limit of 50 total tags. This ensures
backwards compat for the tag additions.
2026-05-13 14:43:50 -07:00
Tom Keller
3f7e1b63d7
chore: update documentation for environment workflows ( #1766 )
...
Closes #1238 .
2026-05-11 23:08:10 +00:00
Tom Keller
8d52d05d7a
feat: support custom STS endpoints ( #1762 )
...
Closes #1067 . This is a advanced option
and is not needed for most deployments.
2026-05-07 14:50:17 -07:00
Tom Keller
61f50f630f
feat: Allow custom session tags to be passed when assuming a role ( #1759 )
...
* Add possibility to input custom session tags
* Use json for input to custom-tags, add documentation for custom-tags
* Add more examples
* Simplify example to avoid parse error
* Add input validation for custom tags
* Fix unit tests for custom-tags
* Add debugging message
* Skip failing test for now
* Build package
* Remove some unused validation for custom tags
* feat: add validation for custom session tags
Harden the custom-tags feature against misuse and
misconfiguration:
- Validate input is a JSON object (reject arrays, primitives, null)
- Enforce STS tag constraints: key length (128), value length (256),
allowed characters
- Reject nested object/array values that would silently stringify to
'[object Object]'
- Block overriding default session tags (GitHub, Repository,
Workflow, etc.)
- Enforce 50-tag session limit
- Warn when custom-tags used with OIDC or web identity
- Fix missing await on helpers test assertion
- Remove unused CUSTOM_TAGS_JSON_INPUTS fixture
- Normalize test mocking to vi.mocked() pattern
---------
Co-authored-by: Sylvain Verly <sylvain.verly@gmail.com >
2026-05-06 15:22:56 -07:00
Tom Keller
a7f0c828ac
feat: Support usage of AWS Profiles ( #1696 )
...
* Support usage of AWS Profiles
* squash merge main updates w feature branch
Squashed commit of the following:
commit ef2df4679f908ff30d5a711258ace2fa906c4bf3
Author: Michael Lehmann <lehmanmj@amazon.com >
Date: Tue Mar 17 11:24:04 2026 -0700
dist update
commit db3779a0e9
Author: Jan Feddern <jf@novatec-gmbh.de >
Date: Sun Dec 21 11:28:36 2025 +0100
Support usage of AWS Profiles
* chore: Update dist
* consistent outputEnvCredentials
* take out tests temporarily
* chore: Update dist
* debug changes for static creds
* remove debug and only cleanup profile if it was set
* formatting fixes + remove profile from cleanup test
* feat: Support usage of AWS Profiles
Adds a config option to support writing to profile files instead of
exporting environment variables.
Closes #1594 . Closes #1586 . Closes #112 .
* chore: fix failing test case and windows path
* chore: lint project markdown files
* chore: update scripts in package.json and tsconfig update
* make env vars consistent, readme linting
* debug for profile path env vars
* remove debug
* remove profile backups
* error if we try to overwrite
* add option to overwrite existing profiles
* tests for overwrite option
* default to no env vars
* remove default from action file
* add static credential env var support
* validation fix for static creds multi profile
* debug sleep for static creds validation
* wait syntax
* undo sleep for creds validate
* test coverage, readme/action yml updates, validate creds later on self-hosted runner
* security dependency updates
* chore(deps-dev): bump @biomejs/biome from 2.4.8 to 2.4.10 (#1709 )
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome ) from 2.4.8 to 2.4.10.
- [Release notes](https://github.com/biomejs/biome/releases )
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md )
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.4.10/packages/@biomejs/biome )
---
updated-dependencies:
- dependency-name: "@biomejs/biome"
dependency-version: 2.4.10
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps-dev): bump @aws-sdk/credential-provider-env (#1713 )
Bumps [@aws-sdk/credential-provider-env](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/credential-provider-env ) from 3.972.22 to 3.972.24.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases )
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-env/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-env )
---
updated-dependencies:
- dependency-name: "@aws-sdk/credential-provider-env"
dependency-version: 3.972.24
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore: Update dist
* chore(deps): bump @aws-sdk/client-sts from 3.1015.0 to 3.1020.0 (#1710 )
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts ) from 3.1015.0 to 3.1020.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases )
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1020.0/clients/client-sts )
---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
dependency-version: 3.1020.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore: Update dist
* fix: do not write empty profile files
Also cleanup fix, additional test, README typo cleanup
* linting fix
* chore: linting fix
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: Jan Feddern <jf@novatec-gmbh.de >
Co-authored-by: Michael Lehmann <lehmanmj@amazon.com >
Co-authored-by: GitHub Actions <github-aws-sdk-osds-automation@amazon.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 16:27:00 -07:00
Tom Keller
11b1c58b24
feat: add skip cleanup option ( #1716 )
...
Closes #1545
2026-04-03 15:00:34 -07:00
Alexander Schwenn
7a319c378c
chore: fix links for OpenID Connect subject claims in README ( #1695 )
...
Updated links in README to point to the correct documentation sections for OpenID Connect subject claims.
2026-03-23 16:29:42 -07:00
Henry Griffiths
0f01265ceb
chore: update readme version to v6.0.0 ( #1642 )
2026-02-05 09:53:33 -08:00
kellertk
4f2ba7fe9c
feat: updates for transitive tagging
2026-01-27 15:56:05 -08:00
Henry Griffiths
a032176f30
chore: update readme version to v5.1.1
2026-01-27 15:45:45 -08:00
Michael Lehmann
fd1fab4c46
Update README.md ( #1544 )
2026-01-27 15:45:45 -08:00
Henry Griffiths
ad637adc0d
chore: update readme version to v5.1.0 ( #1506 )
2026-01-27 15:45:44 -08:00
Tom Keller
a87e741eba
feat: Add global timeout support ( #1487 )
2026-01-27 15:45:43 -08:00
Henry Griffiths
af208eb863
chore: update readme version to v5 ( #1469 )
2026-01-27 15:45:43 -08:00
Tom Keller
0a6b7158f2
chore: Fix markdown link formatting in README.md ( #1466 )
2026-01-27 15:45:43 -08:00
Tom Keller
ecfe99e00b
chore: update README with versioning ( #1465 )
...
* chore: update README with versioning and license info
* chore: fix typo
2026-01-27 15:45:43 -08:00
Tom Keller
9fb1716ceb
feat: support account id allowlist ( #1456 )
...
* feat: support account id allowlist
* chore: update readme
---------
Co-authored-by: Michael Lehmann <lehmanmj@amazon.com >
2026-01-27 15:45:43 -08:00
Tom Keller
4f0bc4ee1c
feat: add skip OIDC option ( #1458 )
2026-01-27 15:45:43 -08:00
Tom Keller
80ed412f2c
fix: update readme to 4.3.1 ( #1424 )
...
This is a fix instead of a chore to force a 4.3.1 tag
Release-as: 4.3.1
2026-01-27 15:44:32 -08:00
Michael Lehmann
979931c880
Update README.md
...
update readme with latest version
2026-01-27 15:44:32 -08:00
Michael Lehmann
5858805023
Revert "Merge pull request #1415 from aws-actions/lehmanmj-patch-1"
2026-01-27 15:44:32 -08:00
Michael Lehmann
2a9d16e130
Update README.md
...
update README to note that authenticated-arn value is output.
also changed version numbers to reflect new version.
2026-01-27 15:44:32 -08:00
Henry Griffiths
a16a4a650d
fix(docs): readme samples versioning
2026-01-27 15:44:09 -08:00
Michael Lehmann
5106596545
Update README.md
...
note that the expiration is listed in the readme as an output.
2026-01-27 15:44:07 -08:00
Alisha Kulkarni
09c6ab0945
Update README.md - Spelling correction
2026-01-27 15:43:50 -08:00
kellertk
9520a4e0cd
chore: Revise readme
2026-01-27 15:43:50 -08:00
Jizu Sun
09242f526d
docs: fix the wrong example region for China partitation
2026-01-27 15:43:50 -08:00
Michael Lehmann
e378c2d267
fix to make action still run
2026-01-27 15:43:50 -08:00
Michael Lehmann
12acc19c37
add output-env-credentials flag (defaults to true)
2026-01-27 15:43:46 -08:00
Dan Markhasin
3efb5d271f
Update README.md
...
Fixed README to reflect the actual names of the output variables
2026-01-27 15:42:54 -08:00
Michael Lehmann
5f34186b4f
document outputs in readme
2026-01-27 15:42:54 -08:00
Michael Lehmann
bd4992e70f
Update README.md
...
update readme.md to provide a suggestion for altering the role-session-name for easier auditability
2026-01-27 15:42:53 -08:00
Michael Lehmann
640ff09de4
Update README.md
2026-01-27 15:42:53 -08:00
Alisha Kulkarni
cd5db3dc55
Update README.md
...
Updated version tags in examples to reflect the latest semantic version.
2026-01-27 15:42:53 -08:00
Massimo Maino
232435c0c0
feat: add support to define transitive tag keys
2025-03-28 14:37:26 +01:00
Michael Lehmann
eb70354fb4
feat: idempotent fetch ( #1289 )
...
* Add functionality to re-use existing credentials
* Finish adding use-existing-credentials logic
* Add testing for use-existing-credentials
* Update README
* feat: finalize use-exisiting-credentials feature
---------
Co-authored-by: Tom Keller <kellertk@amazon.com >
2025-02-07 16:24:45 -08:00
Max Rabin
e0fc2428cc
Update example ARN of China Role ( #1025 )
...
Co-authored-by: Tom Keller <1083460+kellertk@users.noreply.github.com >
2024-03-12 17:17:29 +00:00
Tom Keller
c754bf3531
chore: minor README update
2024-02-16 10:19:19 -08:00
Tom Keller
0a785df9d6
chore: fix README typos
2024-02-16 10:13:23 -08:00
Tom Keller
f6445e06fc
chore: minor README update
2024-02-09 17:00:57 -08:00
Tom Keller
40c1389cab
chore: minor README update
2024-02-09 16:57:50 -08:00
Tom Keller
01c96af67c
chore: update README
...
* Removed table of contents (auto-generated by GitHub now)
* Added list of option section
* Reformatted to 80 columns where possible
* Clarified that we use the JS credential flow. Fixes #962
* Mention role name limitation. Fixes #953
2024-02-09 16:49:12 -08:00
Tim Finnigan
a30bce87e0
chore: update README to note requirement for self-hosted runners using v4 ( #941 )
...
* add note about using node20
* rever license changes
---------
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
2024-01-09 17:02:18 +00:00
Tim Finnigan
3e19f1cabc
fix provider URL ( #907 )
...
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
2023-11-09 23:52:38 +00:00
James Cook
e49c9972c2
Fix to README: Link to details on Assuming a Role goes nowhere ( #878 )
...
Fixes #877 Link to details on Assuming a Role goes nowhere
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
2023-10-10 19:07:01 +00:00
Yasmine Talby
010d0da01d
chore: release v4.0.1 ( #876 )
2023-10-03 11:28:23 -07:00
Justin Plock
f31c158843
feat: Recommending using OIDC ( #871 )
...
* Recommending using OIDC
* Added tests
* fix test and package
* update readme
---------
Co-authored-by: peterwoodworth <woodwoop@amazon.com >
2023-09-29 21:05:32 +00:00
Peter Woodworth
8c3f20df09
chore: release v4 ( #840 )
...
* chore: release v4
* chore: remove node from matrix in integ tests
* chore: update changelog
2023-09-11 14:52:44 -07:00