Compare commits

..

1 Commits

Author SHA1 Message Date
Tom Keller 2748f18272 chore(docs): document immutable OIDC subject claim
GitHub made the OIDC `sub` claim immutable for repositories created on
github.com on or after 2026-04-23 (and older repos that opt in). The claim
now appends the numeric org and repository IDs after each name, separated by
`@`, e.g. `repo:org@123456/repo@789012:ref:refs/heads/main`.

Closes #1888.
2026-07-15 10:48:06 -07:00
12 changed files with 3027 additions and 4958 deletions
+1 -1
View File
@@ -15,7 +15,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
name: Stale issue job name: Stale issue job
steps: steps:
- uses: aws-actions/stale-issue-cleanup@v7 - uses: aws-actions/stale-issue-cleanup@v6
with: with:
# Setting messages to an empty string will cause the automation to skip # Setting messages to an empty string will cause the automation to skip
# that category # that category
+1 -1
View File
@@ -1,5 +1,5 @@
{ {
".release-please-manifest.json": "4.0.2", ".release-please-manifest.json": "4.0.2",
"package.json": "6.0.0", "package.json": "6.0.0",
".": "6.2.3" ".": "6.2.2"
} }
-8
View File
@@ -2,14 +2,6 @@
All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines. All notable changes to this project will be documented in this file. See [standard-version](https://github.com/conventional-changelog/standard-version) for commit guidelines.
## [6.2.3](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3) (2026-07-22)
### Bug Fixes
* attach git credentials before Tag Major Version push ([#1877](https://github.com/aws-actions/configure-aws-credentials/issues/1877)) ([9ae780b](https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482))
* PackedPolicyTooLarge detection in STS tags ([#1899](https://github.com/aws-actions/configure-aws-credentials/issues/1899)) ([fa8d6a5](https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb))
## [6.2.2](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2) (2026-07-07) ## [6.2.2](https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2) (2026-07-07)
-6
View File
@@ -28,12 +28,6 @@ these are incredibly useful:
- Any modifications you've made relevant to the bug - Any modifications you've made relevant to the bug
- Anything unusual about your environment or deployment - Anything unusual about your environment or deployment
We also ask that you refrain from opening issues via the `gh` CLI or GitHub
API. These methods bypass our issue templates and therefore don't apply the
proper labels or workflows that we use. Note that AI agents typically do not
properly use issue templates. Issues that don't have the proper labels
applied may be closed without comment.
## Contributing via Pull Requests ## Contributing via Pull Requests
Contributions via pull requests are much appreciated. Before sending us a pull Contributions via pull requests are much appreciated. Before sending us a pull
+18 -18
View File
@@ -61,7 +61,7 @@ Authenticate to AWS in GitHub Actions (and others)! Works especially well with
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Configure AWS Credentials - name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
role-to-assume: <Role ARN you created in step 2> role-to-assume: <Role ARN you created in step 2>
aws-region: <AWS Region you want to use> aws-region: <AWS Region you want to use>
@@ -250,7 +250,7 @@ specify the profile name as an environment variable in the job step:
```yaml ```yaml
- name: Configure AWS Credentials - name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-1 aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789100:role/my-role role-to-assume: arn:aws:iam::123456789100:role/my-role
@@ -268,14 +268,14 @@ step environment variables:
```yaml ```yaml
- name: Configure AWS credentials - name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-1 aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789100:role/my-first-role role-to-assume: arn:aws:iam::123456789100:role/my-first-role
aws-profile: firstRoleInChain aws-profile: firstRoleInChain
- name: assume second role - name: assume second role
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
role-to-assume: arn:aws:iam::987654321000:role/my-second-role role-to-assume: arn:aws:iam::987654321000:role/my-second-role
@@ -311,7 +311,7 @@ this action will always consider the `HTTP_PROXY` environment variable.
Manually configured proxy: Manually configured proxy:
```yaml ```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
role-to-assume: my-github-actions-role role-to-assume: my-github-actions-role
@@ -458,7 +458,7 @@ line.
<summary>Inline session policy examples</summary> <summary>Inline session policy examples</summary>
```yaml ```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}' inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
``` ```
@@ -466,7 +466,7 @@ with:
Or we can have a nicely formatted JSON as well: Or we can have a nicely formatted JSON as well:
```yaml ```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
inline-session-policy: >- inline-session-policy: >-
{ {
@@ -494,7 +494,7 @@ the role.
<summary>Managed session policy examples</summary> <summary>Managed session policy examples</summary>
```yaml ```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
``` ```
@@ -502,7 +502,7 @@ with:
And we can pass multiple managed policies likes this: And we can pass multiple managed policies likes this:
```yaml ```yaml
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
managed-session-policies: | managed-session-policies: |
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
@@ -548,7 +548,7 @@ specify the audience through the `audience` input:
```yaml ```yaml
- name: Configure AWS Credentials for China region audience - name: Configure AWS Credentials for China region audience
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
audience: sts.amazonaws.com.cn audience: sts.amazonaws.com.cn
aws-region: cn-northwest-1 aws-region: cn-northwest-1
@@ -708,7 +708,7 @@ Provider. The audience would still be `sts.amazonaws.com` by default.
```yaml ```yaml
- name: Configure AWS Credentials - name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
@@ -724,13 +724,13 @@ environment variable and use it to assume the role
```yaml ```yaml
- name: Configure AWS Credentials - name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
role-session-name: MySessionName role-session-name: MySessionName
- name: Configure other AWS Credentials - name: Configure other AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
role-to-assume: arn:aws:iam::987654321000:role/my-second-role role-to-assume: arn:aws:iam::987654321000:role/my-second-role
@@ -752,7 +752,7 @@ alternatively, the `TagSession` permission can be omitted if you are using the
```yaml ```yaml
- name: Configure AWS Credentials - name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -773,7 +773,7 @@ like `role-to-assume: my-github-actions-role`.
```yaml ```yaml
- name: Configure AWS Credentials 1 - name: Configure AWS Credentials 1
id: creds id: creds
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
@@ -782,7 +782,7 @@ like `role-to-assume: my-github-actions-role`.
run: | run: |
aws sts get-caller-identity aws sts get-caller-identity
- name: Configure AWS Credentials 2 - name: Configure AWS Credentials 2
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-2 aws-region: us-east-2
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }} aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
@@ -813,14 +813,14 @@ provided.
```yaml ```yaml
- name: Configure AWS Credentials for Dev - name: Configure AWS Credentials for Dev
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-east-1 aws-region: us-east-1
role-to-assume: arn:aws:iam::111111111111:role/dev-role role-to-assume: arn:aws:iam::111111111111:role/dev-role
aws-profile: dev aws-profile: dev
- name: Configure AWS Credentials for Prod - name: Configure AWS Credentials for Prod
uses: aws-actions/configure-aws-credentials@v6.2.3 uses: aws-actions/configure-aws-credentials@v6.1.0
with: with:
aws-region: us-west-2 aws-region: us-west-2
role-to-assume: arn:aws:iam::222222222222:role/prod-role role-to-assume: arn:aws:iam::222222222222:role/prod-role
+23 -23
View File
@@ -222,7 +222,7 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
The following npm package may be included in this product: The following npm package may be included in this product:
- @aws-sdk/client-sts@3.1116.0 - @aws-sdk/client-sts@3.1086.0
This package contains the following license: This package contains the following license:
@@ -432,9 +432,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/signature-v4-multi-region@3.996.46 - @aws-sdk/signature-v4-multi-region@3.996.39
- @smithy/core@3.33.3 - @smithy/core@3.29.3
- @smithy/types@4.17.2 - @smithy/types@4.16.1
These packages each contain the following license: These packages each contain the following license:
@@ -832,7 +832,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
The following npm package may be included in this product: The following npm package may be included in this product:
- @aws-sdk/core@3.977.9 - @aws-sdk/core@3.975.1
This package contains the following license: This package contains the following license:
@@ -1042,16 +1042,16 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-env@3.972.70 - @aws-sdk/credential-provider-env@3.972.57
- @aws-sdk/credential-provider-ini@3.973.15 - @aws-sdk/credential-provider-ini@3.973.1
- @aws-sdk/credential-provider-node@3.972.81 - @aws-sdk/credential-provider-node@3.972.67
- @aws-sdk/token-providers@3.1116.0 - @aws-sdk/token-providers@3.1083.0
- @aws-sdk/types@3.974.5 - @aws-sdk/types@3.974.0
- @aws-sdk/xml-builder@3.972.40 - @aws-sdk/xml-builder@3.972.34
- @smithy/credential-provider-imds@4.5.2 - @smithy/credential-provider-imds@4.4.8
- @smithy/fetch-http-handler@5.7.2 - @smithy/fetch-http-handler@5.6.5
- @smithy/node-http-handler@4.11.3 - @smithy/node-http-handler@4.9.5
- @smithy/signature-v4@5.6.12 - @smithy/signature-v4@5.6.4
These packages each contain the following license: These packages each contain the following license:
@@ -1261,9 +1261,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-process@3.972.70 - @aws-sdk/credential-provider-process@3.972.57
- @aws-sdk/credential-provider-sso@3.973.14 - @aws-sdk/credential-provider-sso@3.973.1
- @aws-sdk/credential-provider-web-identity@3.972.76 - @aws-sdk/credential-provider-web-identity@3.972.63
These packages each contain the following license: These packages each contain the following license:
@@ -1473,9 +1473,9 @@ Apache License
The following npm packages may be included in this product: The following npm packages may be included in this product:
- @aws-sdk/credential-provider-http@3.972.72 - @aws-sdk/credential-provider-http@3.972.59
- @aws-sdk/credential-provider-login@3.972.77 - @aws-sdk/credential-provider-login@3.972.63
- @aws-sdk/nested-clients@3.997.44 - @aws-sdk/nested-clients@3.997.31
These packages each contain the following license: These packages each contain the following license:
@@ -1485,7 +1485,7 @@ Apache-2.0
The following npm package may be included in this product: The following npm package may be included in this product:
- ip-address@10.4.0 - ip-address@10.2.0
This package contains the following license: This package contains the following license:
@@ -1740,7 +1740,7 @@ SOFTWARE.
The following npm package may be included in this product: The following npm package may be included in this product:
- undici@6.28.0 - undici@6.27.0
This package contains the following license: This package contains the following license:
Generated Vendored
+6 -88
View File
@@ -1929,11 +1929,7 @@ var require_request = __commonJS({
} else if (typeof val[i] === "object") { } else if (typeof val[i] === "object") {
throw new InvalidArgumentError(`invalid ${key} header`); throw new InvalidArgumentError(`invalid ${key} header`);
} else { } else {
const str = `${val[i]}`; arr.push(`${val[i]}`);
if (!isValidHeaderValue(str)) {
throw new InvalidArgumentError(`invalid ${key} header`);
}
arr.push(str);
} }
} }
val = arr; val = arr;
@@ -1945,9 +1941,6 @@ var require_request = __commonJS({
val = ""; val = "";
} else { } else {
val = `${val}`; val = `${val}`;
if (!isValidHeaderValue(val)) {
throw new InvalidArgumentError(`invalid ${key} header`);
}
} }
if (headerName === "host") { if (headerName === "host") {
if (request.host !== null) { if (request.host !== null) {
@@ -5678,7 +5671,6 @@ var require_client_h1 = __commonJS({
RequestContentLengthMismatchError, RequestContentLengthMismatchError,
ResponseContentLengthMismatchError, ResponseContentLengthMismatchError,
RequestAbortedError, RequestAbortedError,
InvalidArgumentError,
HeadersTimeoutError, HeadersTimeoutError,
HeadersOverflowError, HeadersOverflowError,
SocketError, SocketError,
@@ -6405,16 +6397,8 @@ var require_client_h1 = __commonJS({
} }
body = bodyStream.stream; body = bodyStream.stream;
contentLength = bodyStream.length; contentLength = bodyStream.length;
} else if (util.isBlobLike(body) && request.contentType == null) { } else if (util.isBlobLike(body) && request.contentType == null && body.type) {
const contentType = body.type; headers.push("content-type", body.type);
if (contentType) {
const contentTypeValue = `${contentType}`;
if (!util.isValidHeaderValue(contentTypeValue)) {
util.errorRequest(client, request, new InvalidArgumentError("invalid content-type header"));
return false;
}
headers.push("content-type", contentTypeValue);
}
} }
if (body && typeof body.read === "function") { if (body && typeof body.read === "function") {
body.read(0); body.read(0);
@@ -8966,24 +8950,6 @@ var require_retry_handler = __commonJS({
const current = Date.now(); const current = Date.now();
return new Date(retryAfter).getTime() - current; return new Date(retryAfter).getTime() - current;
} }
function validatePartialResponseContentLength(headers, range, statusCode, retryCount) {
const contentLength = headers["content-length"];
if (contentLength == null) {
return null;
}
if (!Number.isFinite(range.start) || !Number.isFinite(range.end)) {
return null;
}
const length = Number(contentLength);
const expectedLength = range.end - range.start + 1;
if (!Number.isFinite(length) || length !== expectedLength) {
return new RequestRetryError("Content-Length mismatch", statusCode, {
headers,
data: { count: retryCount }
});
}
return null;
}
var RetryHandler = class _RetryHandler { var RetryHandler = class _RetryHandler {
constructor(opts, handlers) { constructor(opts, handlers) {
const { retryOptions, ...dispatchOpts } = opts; const { retryOptions, ...dispatchOpts } = opts;
@@ -9156,11 +9122,6 @@ var require_retry_handler = __commonJS({
); );
return false; return false;
} }
const contentLengthError = validatePartialResponseContentLength(headers, contentRange, statusCode, this.retryCount);
if (contentLengthError != null) {
this.abort(contentLengthError);
return false;
}
const { start, size, end = size - 1 } = contentRange; const { start, size, end = size - 1 } = contentRange;
assert(this.start === start, "content-range mismatch"); assert(this.start === start, "content-range mismatch");
assert(this.end == null || this.end === end, "content-range mismatch"); assert(this.end == null || this.end === end, "content-range mismatch");
@@ -9178,11 +9139,6 @@ var require_retry_handler = __commonJS({
statusMessage statusMessage
); );
} }
const contentLengthError = validatePartialResponseContentLength(headers, range, statusCode, this.retryCount);
if (contentLengthError != null) {
this.abort(contentLengthError);
return false;
}
const { start, size, end = size - 1 } = range; const { start, size, end = size - 1 } = range;
assert( assert(
start != null && Number.isFinite(start), start != null && Number.isFinite(start),
@@ -16028,48 +15984,14 @@ var require_util6 = __commonJS({
for (let i = 0; i < path.length; ++i) { for (let i = 0; i < path.length; ++i) {
const code = path.charCodeAt(i); const code = path.charCodeAt(i);
if (code < 32 || // exclude CTLs (0-31) if (code < 32 || // exclude CTLs (0-31)
code > 126 || // exclude DEL and non-ascii code === 127 || // DEL
code === 59) { code === 59) {
throw new Error("Invalid cookie path"); throw new Error("Invalid cookie path");
} }
} }
} }
function isLetterOrDigit(code) {
return code >= 48 && code <= 57 || // 0-9
code >= 65 && code <= 90 || // A-Z
code >= 97 && code <= 122;
}
function validateCookieDomain(domain) { function validateCookieDomain(domain) {
if (domain === " ") { if (domain.startsWith("-") || domain.endsWith(".") || domain.endsWith("-")) {
return;
}
if (domain.length > 255) {
throw new Error("Invalid cookie domain");
}
let labelLength = 0;
for (let i = 0; i < domain.length; ++i) {
const code = domain.charCodeAt(i);
if (code === 46) {
if (labelLength === 0) {
throw new Error("Invalid cookie domain");
}
if (domain.charCodeAt(i - 1) === 45) {
throw new Error("Invalid cookie domain");
}
labelLength = 0;
continue;
}
if (labelLength === 0 && !isLetterOrDigit(code)) {
throw new Error("Invalid cookie domain");
}
if (!isLetterOrDigit(code) && code !== 45) {
throw new Error("Invalid cookie domain");
}
if (++labelLength > 63) {
throw new Error("Invalid cookie domain");
}
}
if (labelLength === 0 || domain.charCodeAt(domain.length - 1) === 45) {
throw new Error("Invalid cookie domain"); throw new Error("Invalid cookie domain");
} }
} }
@@ -16152,11 +16074,7 @@ var require_util6 = __commonJS({
throw new Error("Invalid unparsed"); throw new Error("Invalid unparsed");
} }
const [key, ...value] = part.split("="); const [key, ...value] = part.split("=");
const trimmedKey = key.trim(); out.push(`${key.trim()}=${value.join("=")}`);
const joinedValue = value.join("=");
validateCookieName(trimmedKey);
validateCookieValue(joinedValue);
out.push(`${trimmedKey}=${joinedValue}`);
} }
return out.join("; "); return out.join("; ");
} }
Generated Vendored
+2533 -4352
View File
File diff suppressed because it is too large Load Diff
+424 -444
View File
File diff suppressed because it is too large Load Diff
+10 -10
View File
@@ -1,7 +1,7 @@
{ {
"name": "configure-aws-credentials", "name": "configure-aws-credentials",
"description": "A GitHub Action to configure AWS credentials", "description": "A GitHub Action to configure AWS credentials",
"version": "6.2.3", "version": "6.2.2",
"scripts": { "scripts": {
"build": "tsc", "build": "tsc",
"lint": "biome check --error-on-warnings ./src ./test && markdownlint -i node_modules -i CHANGELOG.md '**/*.md'", "lint": "biome check --error-on-warnings ./src ./test && markdownlint -i node_modules -i CHANGELOG.md '**/*.md'",
@@ -17,25 +17,25 @@
"organization": true "organization": true
}, },
"devDependencies": { "devDependencies": {
"@aws-sdk/credential-provider-env": "^3.972.70", "@aws-sdk/credential-provider-env": "^3.972.57",
"@biomejs/biome": "2.5.10", "@biomejs/biome": "2.5.3",
"@smithy/property-provider": "^4.5.2", "@smithy/property-provider": "^4.4.8",
"@types/node": "^26.2.0", "@types/node": "^26.1.1",
"@vitest/coverage-v8": "4.1.10", "@vitest/coverage-v8": "4.1.10",
"aws-sdk-client-mock": "^4.1.0", "aws-sdk-client-mock": "^4.1.0",
"esbuild": "^0.28.2", "esbuild": "^0.28.1",
"generate-license-file": "^4.2.1", "generate-license-file": "^4.2.1",
"json-schema": "^0.4.0", "json-schema": "^0.4.0",
"markdownlint-cli": "^0.49.1", "markdownlint-cli": "^0.49.0",
"memfs": "^4.68.1", "memfs": "^4.64.0",
"standard-version": "^9.5.0", "standard-version": "^9.5.0",
"typescript": "^7.0.2", "typescript": "^7.0.2",
"vitest": "4.1.10" "vitest": "4.1.10"
}, },
"dependencies": { "dependencies": {
"@actions/core": "^3.0.1", "@actions/core": "^3.0.1",
"@aws-sdk/client-sts": "^3.1116.0", "@aws-sdk/client-sts": "^3.1086.0",
"@smithy/node-http-handler": "^4.11.3", "@smithy/node-http-handler": "^4.9.5",
"proxy-agent": "^8.0.2" "proxy-agent": "^8.0.2"
}, },
"keywords": [ "keywords": [
+6 -2
View File
@@ -2,7 +2,11 @@ import assert from 'node:assert';
import path from 'node:path'; import path from 'node:path';
import * as core from '@actions/core'; import * as core from '@actions/core';
import type { AssumeRoleCommandInput, STSClient, Tag } from '@aws-sdk/client-sts'; import type { AssumeRoleCommandInput, STSClient, Tag } from '@aws-sdk/client-sts';
import { AssumeRoleCommand, AssumeRoleWithWebIdentityCommand } from '@aws-sdk/client-sts'; import {
AssumeRoleCommand,
AssumeRoleWithWebIdentityCommand,
PackedPolicyTooLargeException,
} from '@aws-sdk/client-sts';
import type { CredentialsClient } from './CredentialsClient'; import type { CredentialsClient } from './CredentialsClient';
import { errorMessage, isDefined, readFileUtf8, sanitizeGitHubVariables } from './helpers'; import { errorMessage, isDefined, readFileUtf8, sanitizeGitHubVariables } from './helpers';
@@ -61,7 +65,7 @@ async function assumeRoleWithCredentials(params: AssumeRoleCommandInput, client:
const creds = await client.send(new AssumeRoleCommand({ ...params })); const creds = await client.send(new AssumeRoleCommand({ ...params }));
return creds; return creds;
} catch (error) { } catch (error) {
if ((error as { name?: string })?.name === 'PackedPolicyTooLargeException') { if (error instanceof PackedPolicyTooLargeException) {
core.info('Session tag size is too large; dropping droppable tags and retrying.'); core.info('Session tag size is too large; dropping droppable tags and retrying.');
const droppableKeys = new Set(DROPPABLE_TAG_SOURCES.map((s) => s.key)); const droppableKeys = new Set(DROPPABLE_TAG_SOURCES.map((s) => s.key));
params.Tags = params.Tags?.filter((tag) => !droppableKeys.has(tag.Key ?? '')); params.Tags = params.Tags?.filter((tag) => !droppableKeys.has(tag.Key ?? ''));
+5 -5
View File
@@ -3,6 +3,7 @@ import {
AssumeRoleCommand, AssumeRoleCommand,
AssumeRoleWithWebIdentityCommand, AssumeRoleWithWebIdentityCommand,
GetCallerIdentityCommand, GetCallerIdentityCommand,
PackedPolicyTooLargeException,
STSClient, STSClient,
} from '@aws-sdk/client-sts'; } from '@aws-sdk/client-sts';
import { mockClient } from 'aws-sdk-client-mock'; import { mockClient } from 'aws-sdk-client-mock';
@@ -330,11 +331,10 @@ describe('Configure AWS Credentials', {}, () => {
}); });
it('drops droppable tags and retries on PackedPolicyTooLargeException', {}, async () => { it('drops droppable tags and retries on PackedPolicyTooLargeException', {}, async () => {
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.IAM_ASSUMEROLE_INPUTS)); vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.IAM_ASSUMEROLE_INPUTS));
// Reject with a plain error carrying only the `name`, NOT an instance of the SDK class. This mockedSTSClient
// mirrors the bundled action, where the error can be deserialized by a second, non-identical .on(AssumeRoleCommand)
// copy of PackedPolicyTooLargeException so `instanceof` fails; the recovery must key off `name`. .rejectsOnce(new PackedPolicyTooLargeException({ message: 'too large', $metadata: {} }))
const packedPolicyError = Object.assign(new Error('too large'), { name: 'PackedPolicyTooLargeException' }); .resolvesOnce(mocks.outputs.STS_CREDENTIALS);
mockedSTSClient.on(AssumeRoleCommand).rejectsOnce(packedPolicyError).resolvesOnce(mocks.outputs.STS_CREDENTIALS);
await run(); await run();
expect(core.info).toHaveBeenCalledWith('Session tag size is too large; dropping droppable tags and retrying.'); expect(core.info).toHaveBeenCalledWith('Session tag size is too large; dropping droppable tags and retrying.');
const retryInput = mockedSTSClient.commandCalls(AssumeRoleCommand)[1].args[0].input; const retryInput = mockedSTSClient.commandCalls(AssumeRoleCommand)[1].args[0].input;