Compare commits

..

12 Commits

Author SHA1 Message Date
dependabot[bot] 5e00a36cd3 chore(deps-dev): bump vitest from 4.1.10 to 4.1.11
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.10 to 4.1.11.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-01 03:55:47 +00:00
GitHub Actions ebc93aaaca chore: Update dist 2026-09-01 03:54:04 +00:00
dependabot[bot] 00e2a5c25b chore(deps): bump @aws-sdk/client-sts from 3.1116.0 to 3.1121.0 (#1948)
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) from 3.1116.0 to 3.1121.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1121.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1121.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 03:53:30 +00:00
dependabot[bot] ae9b682f10 chore(deps-dev): bump @biomejs/biome from 2.5.10 to 2.5.11 (#1945)
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.10 to 2.5.11.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.11/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 03:49:59 +00:00
dependabot[bot] 49dd1a0ccd chore(deps-dev): bump @types/node from 26.2.0 to 26.4.0 (#1947)
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.2.0 to 26.4.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 03:46:53 +00:00
GitHub Actions f7b1b3335e chore: Update dist 2026-09-01 03:44:06 +00:00
dependabot[bot] a76dbc9e62 chore(deps-dev): bump generate-license-file from 4.2.1 to 4.2.4 (#1946)
Bumps [generate-license-file](https://github.com/TobyAndToby/generate-license-file/tree/HEAD/packages/generate-license-file) from 4.2.1 to 4.2.4.
- [Release notes](https://github.com/TobyAndToby/generate-license-file/releases)
- [Commits](https://github.com/TobyAndToby/generate-license-file/commits/v4.2.4/packages/generate-license-file)

---
updated-dependencies:
- dependency-name: generate-license-file
  dependency-version: 4.2.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-01 03:43:39 +00:00
GitHub Actions b7a1386e5b docs: update README version references to v6.2.4 2026-08-31 23:25:32 +00:00
AWS SDKs and Tools bot cbe3b39273 chore(main): release 6.2.4 (#1942)
Co-authored-by: Tom Keller <1083460+kellertk@users.noreply.github.com>
2026-08-31 23:17:23 +00:00
dependabot[bot] 58065db07c chore(deps): bump js-yaml (#1944)
Bumps  and [js-yaml](https://github.com/nodeca/js-yaml). These dependencies needed to be updated together.

Updates `js-yaml` from 4.2.0 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.2)

Updates `js-yaml` from 5.2.1 to 5.2.3
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
- dependency-name: js-yaml
  dependency-version: 5.2.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 22:25:41 +00:00
GitHub Actions 609df23709 chore: Update dist 2026-08-31 21:48:01 +00:00
Tom Keller aa6526434b fix: account-ids handling, mask proxy as secret in logs (#1943)
* fix: enforce allowed-account-ids when the list contains empty entries

An empty first element previously short-circuited the allowed account
check. Empty entries are now filtered out and validation applies
whenever any non-empty entry exists.

* fix: enforce allowed-account-ids on the use-existing-credentials path

The early return for valid pre-existing credentials skipped the
allowed-account-ids check, now included.

* fix: reject newlines in names and values when writing profile files

If the profile file writing was enabled, we emitted newlines into the
file verbatim, permitting injecting arbitrary profiles into the file.
Writing now fails instead.

* fix: honor configured STS endpoint for "ambient" credentials

Ambient credential resolution built a bare STS client, so a web-identity
token found by the SDK default chain (e.g. AWS_WEB_IDENTITY_TOKEN_FILE on
a self-hosted runner) was exchanged with public STS instead of any
operator-configured sts-endpoint. Resolution now passes the configured
region, endpoint, and proxy handler to the default provider chain.

* fix: mask proxy URL credentials in job logs

Basic-auth userinfo in the http-proxy input or HTTP(S)_PROXY environment
variables was never registered as a secret, so error messages carrying
the proxy URL printed the credentials unmasked in the job log.

* fix: omit account IDs from the allowed-account-ids failure message

The mismatch error is thrown before exportAccountId registers the
account-id mask, so setFailed wrote the raw account ID (and the
configured allow-list) into a public annotation. (C4)

* chore: remove outdated examples

All of the examples were out of date and we do not have a mechanism for
keeping them up to date. Removed the examples.
2026-08-31 14:31:24 -07:00
7 changed files with 1460 additions and 2196 deletions
+1 -1
View File
@@ -1,5 +1,5 @@
{
".release-please-manifest.json": "4.0.2",
"package.json": "6.0.0",
".": "6.2.3"
".": "6.2.4"
}
+8
View File
@@ -2,6 +2,14 @@
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
## [6.2.4](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4) (2026-08-31)
### Bug Fixes
* account-ids handling, mask proxy as secret in logs ([#1943](https://github.com/aws-actions/configure-aws-credentials/issues/1943)) ([aa65264](https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63))
* skip backoff sleep after the final retryAndBackoff attempt ([#1937](https://github.com/aws-actions/configure-aws-credentials/issues/1937)) ([3852440](https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876))
## [6.2.3](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3) (2026-07-22)
+18 -18
View File
@@ -61,7 +61,7 @@ Authenticate to AWS in GitHub Actions (and others)! Works especially well with
runs-on: ubuntu-latest
steps:
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
role-to-assume: <Role ARN you created in step 2>
aws-region: <AWS Region you want to use>
@@ -250,7 +250,7 @@ specify the profile name as an environment variable in the job step:
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789100:role/my-role
@@ -268,14 +268,14 @@ step environment variables:
```yaml
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789100:role/my-first-role
aws-profile: firstRoleInChain
- name: assume second role
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
@@ -311,7 +311,7 @@ this action will always consider the `HTTP_PROXY` environment variable.
Manually configured proxy:
```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
role-to-assume: my-github-actions-role
@@ -458,7 +458,7 @@ line.
<summary>Inline session policy examples</summary>
```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
```
@@ -466,7 +466,7 @@ with:
Or we can have a nicely formatted JSON as well:
```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
inline-session-policy: >-
{
@@ -494,7 +494,7 @@ the role.
<summary>Managed session policy examples</summary>
```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
```
@@ -502,7 +502,7 @@ with:
And we can pass multiple managed policies likes this:
```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
managed-session-policies: |
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
@@ -548,7 +548,7 @@ specify the audience through the `audience` input:
```yaml
- name: Configure AWS Credentials for China region audience
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
audience: sts.amazonaws.com.cn
aws-region: cn-northwest-1
@@ -709,7 +709,7 @@ Provider. The audience would still be `sts.amazonaws.com` by default.
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
@@ -725,13 +725,13 @@ environment variable and use it to assume the role
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
role-session-name: MySessionName
- name: Configure other AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
@@ -753,7 +753,7 @@ alternatively, the `TagSession` permission can be omitted if you are using the
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -774,7 +774,7 @@ like `role-to-assume: my-github-actions-role`.
```yaml
- name: Configure AWS Credentials 1
id: creds
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
@@ -783,7 +783,7 @@ like `role-to-assume: my-github-actions-role`.
run: |
aws sts get-caller-identity
- name: Configure AWS Credentials 2
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-2
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
@@ -814,14 +814,14 @@ provided.
```yaml
- name: Configure AWS Credentials for Dev
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::111111111111:role/dev-role
aws-profile: dev
- name: Configure AWS Credentials for Prod
uses: aws-actions/configure-aws-credentials@v6.2.3
uses: aws-actions/configure-aws-credentials@v6.2.4
with:
aws-region: us-west-2
role-to-assume: arn:aws:iam::222222222222:role/prod-role
+1 -1
View File
@@ -222,7 +222,7 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
The following npm package may be included in this product:
- @aws-sdk/client-sts@3.1116.0
- @aws-sdk/client-sts@3.1121.0
This package contains the following license:
Generated Vendored
+561 -1223
View File
File diff suppressed because it is too large Load Diff
+865 -947
View File
File diff suppressed because it is too large Load Diff
+6 -6
View File
@@ -1,7 +1,7 @@
{
"name": "configure-aws-credentials",
"description": "A GitHub Action to configure AWS credentials",
"version": "6.2.3",
"version": "6.2.4",
"scripts": {
"build": "tsc",
"lint": "biome check --error-on-warnings ./src ./test && markdownlint -i node_modules -i CHANGELOG.md '**/*.md'",
@@ -18,23 +18,23 @@
},
"devDependencies": {
"@aws-sdk/credential-provider-env": "^3.972.70",
"@biomejs/biome": "2.5.10",
"@biomejs/biome": "2.5.11",
"@smithy/property-provider": "^4.5.2",
"@types/node": "^26.2.0",
"@types/node": "^26.4.0",
"@vitest/coverage-v8": "4.1.10",
"aws-sdk-client-mock": "^4.1.0",
"esbuild": "^0.28.2",
"generate-license-file": "^4.2.1",
"generate-license-file": "^4.2.4",
"json-schema": "^0.4.0",
"markdownlint-cli": "^0.49.1",
"memfs": "^4.68.1",
"standard-version": "^9.5.0",
"typescript": "^7.0.2",
"vitest": "4.1.10"
"vitest": "4.1.11"
},
"dependencies": {
"@actions/core": "^3.0.1",
"@aws-sdk/client-sts": "^3.1116.0",
"@aws-sdk/client-sts": "^3.1121.0",
"@aws-sdk/credential-provider-node": "^3.972.63",
"@smithy/node-http-handler": "^4.11.3",
"proxy-agent": "^8.0.2"