Compare commits

...

63 Commits

Author SHA1 Message Date
Tom Keller a1829d0ba1 chore: remove outdated examples
All of the examples were out of date and we do not have a mechanism for
keeping them up to date. Removed the examples.
2026-08-31 13:26:19 -07:00
Tom Keller 4b8b5e37b4 fix: omit account IDs from the allowed-account-ids failure message
The mismatch error is thrown before exportAccountId registers the
account-id mask, so setFailed wrote the raw account ID (and the
configured allow-list) into a public annotation. (C4)
2026-08-31 13:18:21 -07:00
Tom Keller a05dfa82bd fix: mask proxy URL credentials in job logs
Basic-auth userinfo in the http-proxy input or HTTP(S)_PROXY environment
variables was never registered as a secret, so error messages carrying
the proxy URL printed the credentials unmasked in the job log.
2026-08-31 13:18:21 -07:00
Tom Keller 378a941623 fix: honor configured STS endpoint for "ambient" credentials
Ambient credential resolution built a bare STS client, so a web-identity
token found by the SDK default chain (e.g. AWS_WEB_IDENTITY_TOKEN_FILE on
a self-hosted runner) was exchanged with public STS instead of any
operator-configured sts-endpoint. Resolution now passes the configured
region, endpoint, and proxy handler to the default provider chain.
2026-08-31 13:01:39 -07:00
Tom Keller 82408b69eb fix: reject newlines in names and values when writing profile files
If the profile file writing was enabled, we emitted newlines into the
file verbatim, permitting injecting arbitrary profiles into the file.
Writing now fails instead.
2026-08-31 12:52:53 -07:00
Tom Keller 1f2d3ed486 fix: enforce allowed-account-ids on the use-existing-credentials path
The early return for valid pre-existing credentials skipped the
allowed-account-ids check, now included.
2026-08-31 12:48:42 -07:00
Tom Keller ed5da29eb9 fix: enforce allowed-account-ids when the list contains empty entries
An empty first element previously short-circuited the allowed account
check. Empty entries are now filtered out and validation applies
whenever any non-empty entry exists.
2026-08-31 12:30:08 -07:00
GitHub Actions 7fdbbb8968 chore: Update dist 2026-08-28 18:06:56 +00:00
Zhiwei Liang 3852440c21 fix: skip backoff sleep after the final retryAndBackoff attempt (#1937)
Signed-off-by: Zhiwei Liang <zhiwei.liang@zliang.me>
Co-authored-by: Joseph Klix <jkl@amazon.com>
2026-08-28 18:03:00 +00:00
Joseph Klix c16f89bdf4 mention renamed repos use the new immutable identifiers (#1941) 2026-08-28 10:19:03 -07:00
GitHub Actions 9c362eeba7 chore: Update dist 2026-08-25 03:55:51 +00:00
dependabot[bot] d5f8da8822 chore(deps): bump @aws-sdk/client-sts from 3.1111.0 to 3.1116.0 (#1935)
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) from 3.1111.0 to 3.1116.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1116.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1116.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 03:55:13 +00:00
GitHub Actions 2db24970cf chore: Update dist 2026-08-25 03:52:10 +00:00
dependabot[bot] 58c3b6e457 chore(deps-dev): bump @aws-sdk/credential-provider-env (#1931)
Bumps [@aws-sdk/credential-provider-env](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/credential-provider-env) from 3.972.69 to 3.972.70.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-env/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-env)

---
updated-dependencies:
- dependency-name: "@aws-sdk/credential-provider-env"
  dependency-version: 3.972.70
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 03:51:47 +00:00
GitHub Actions 2630a7c30d chore: Update dist 2026-08-25 03:49:44 +00:00
dependabot[bot] 9cb796df96 chore(deps): bump @smithy/node-http-handler from 4.11.0 to 4.11.3 (#1934)
Bumps [@smithy/node-http-handler](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler) from 4.11.0 to 4.11.3.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/node-http-handler/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/node-http-handler@4.11.3/packages/node-http-handler)

---
updated-dependencies:
- dependency-name: "@smithy/node-http-handler"
  dependency-version: 4.11.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 03:49:13 +00:00
dependabot[bot] 9def7f603e chore(deps-dev): bump @biomejs/biome from 2.5.8 to 2.5.10 (#1933)
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.8 to 2.5.10.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.10/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 03:47:39 +00:00
dependabot[bot] f5c3a50aab chore(deps): bump brace-expansion (#1936)
Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 5.0.5 to 5.0.9
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.5...v5.0.9)

Updates `brace-expansion` from 1.1.14 to 1.1.18
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.5...v5.0.9)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.9
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 03:46:13 +00:00
GitHub Actions 64cf66c882 chore: Update dist 2026-08-25 03:44:43 +00:00
dependabot[bot] af68a47c78 chore(deps-dev): bump @smithy/property-provider from 4.5.0 to 4.5.2 (#1929)
Bumps [@smithy/property-provider](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/property-provider) from 4.5.0 to 4.5.2.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/property-provider/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/property-provider@4.5.2/packages/property-provider)

---
updated-dependencies:
- dependency-name: "@smithy/property-provider"
  dependency-version: 4.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 03:44:13 +00:00
GitHub Actions bcd4089080 chore: Update dist 2026-08-18 04:00:07 +00:00
dependabot[bot] 721b15f0ee chore(deps): bump @aws-sdk/client-sts from 3.1106.0 to 3.1111.0 (#1928)
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) from 3.1106.0 to 3.1111.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1111.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1111.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:59:35 +00:00
dependabot[bot] 0e771c8069 chore(deps-dev): bump esbuild from 0.28.1 to 0.28.2 (#1924)
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.28.1 to 0.28.2.
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](https://github.com/evanw/esbuild/compare/v0.28.1...v0.28.2)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:56:20 +00:00
dependabot[bot] 6e36582a90 chore(deps-dev): bump @smithy/property-provider from 4.4.16 to 4.5.0 (#1922)
Bumps [@smithy/property-provider](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/property-provider) from 4.4.16 to 4.5.0.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/property-provider/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/property-provider@4.5.0/packages/property-provider)

---
updated-dependencies:
- dependency-name: "@smithy/property-provider"
  dependency-version: 4.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:53:20 +00:00
dependabot[bot] 7a26c6cbd2 chore(deps-dev): bump memfs from 4.68.0 to 4.68.1 (#1927)
Bumps [memfs](https://github.com/streamich/memfs) from 4.68.0 to 4.68.1.
- [Release notes](https://github.com/streamich/memfs/releases)
- [Changelog](https://github.com/streamich/memfs/blob/master/CHANGELOG.md)
- [Commits](https://github.com/streamich/memfs/compare/v4.68.0...v4.68.1)

---
updated-dependencies:
- dependency-name: memfs
  dependency-version: 4.68.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:51:04 +00:00
GitHub Actions 83c855008c chore: Update dist 2026-08-18 03:49:31 +00:00
dependabot[bot] e2c213d5f6 chore(deps-dev): bump @aws-sdk/credential-provider-env (#1926)
Bumps [@aws-sdk/credential-provider-env](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/credential-provider-env) from 3.972.68 to 3.972.69.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-env/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-env)

---
updated-dependencies:
- dependency-name: "@aws-sdk/credential-provider-env"
  dependency-version: 3.972.69
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:49:01 +00:00
GitHub Actions fd3f78a69a chore: Update dist 2026-08-18 03:47:26 +00:00
dependabot[bot] ab089d1087 chore(deps): bump @smithy/node-http-handler from 4.9.13 to 4.11.0 (#1925)
Bumps [@smithy/node-http-handler](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler) from 4.9.13 to 4.11.0.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/node-http-handler/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/types@4.11.0/packages/node-http-handler)

---
updated-dependencies:
- dependency-name: "@smithy/node-http-handler"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:46:51 +00:00
dependabot[bot] 0ea2ab0d82 chore(deps-dev): bump @biomejs/biome from 2.5.7 to 2.5.8 (#1923)
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.7 to 2.5.8.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.8/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 03:43:57 +00:00
GitHub Actions 12d377b18d chore: Update dist 2026-08-12 21:51:34 +00:00
dependabot[bot] 3f6acccbef chore(deps): bump @aws-sdk/client-sts from 3.1101.0 to 3.1106.0 (#1919)
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) from 3.1101.0 to 3.1106.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1106.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1106.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 21:50:57 +00:00
dependabot[bot] 9f178b3b31 chore(deps-dev): bump @biomejs/biome from 2.5.6 to 2.5.7 (#1917)
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.6 to 2.5.7.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.7/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 21:47:59 +00:00
GitHub Actions 4c029bab3d chore: Update dist 2026-08-12 21:44:38 +00:00
dependabot[bot] 15313a702c chore(deps-dev): bump @aws-sdk/credential-provider-env (#1918)
Bumps [@aws-sdk/credential-provider-env](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/credential-provider-env) from 3.972.66 to 3.972.67.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-env/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-env)

---
updated-dependencies:
- dependency-name: "@aws-sdk/credential-provider-env"
  dependency-version: 3.972.67
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 21:44:08 +00:00
dependabot[bot] c52a2eac0d chore(deps-dev): bump @types/node from 26.1.2 to 26.2.0 (#1916)
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.2 to 26.2.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 21:39:03 +00:00
dependabot[bot] 87f905da14 chore(deps-dev): bump memfs from 4.64.0 to 4.68.0 (#1920)
Bumps [memfs](https://github.com/streamich/memfs) from 4.64.0 to 4.68.0.
- [Release notes](https://github.com/streamich/memfs/releases)
- [Changelog](https://github.com/streamich/memfs/blob/master/CHANGELOG.md)
- [Commits](https://github.com/streamich/memfs/compare/v4.64.0...v4.68.0)

---
updated-dependencies:
- dependency-name: memfs
  dependency-version: 4.68.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Michael Lehmann <lehmanmj@amazon.com>
2026-08-12 21:26:40 +00:00
Tom Keller ba7d3485af chore: clarify issue template policy (#1921) 2026-08-12 10:13:32 -07:00
Tom Keller 0802eece3e chore: bump stale-issue-cleanup to v7 (#1914) 2026-08-04 11:56:48 -07:00
GitHub Actions b04158f834 chore: Update dist 2026-08-04 03:58:29 +00:00
dependabot[bot] bc56d889a4 chore(deps): bump undici from 6.27.0 to 6.28.0 (#1913)
Bumps [undici](https://github.com/nodejs/undici) from 6.27.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:58:00 +00:00
dependabot[bot] a5fc44c8bc chore(deps-dev): bump @smithy/property-provider from 4.4.15 to 4.4.16 (#1908)
Bumps [@smithy/property-provider](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/property-provider) from 4.4.15 to 4.4.16.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/property-provider/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/property-provider@4.4.16/packages/property-provider)

---
updated-dependencies:
- dependency-name: "@smithy/property-provider"
  dependency-version: 4.4.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:55:10 +00:00
GitHub Actions e6bb36664c chore: Update dist 2026-08-04 03:53:40 +00:00
dependabot[bot] c39789ae94 chore(deps): bump @aws-sdk/client-sts from 3.1096.0 to 3.1101.0 (#1911)
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) from 3.1096.0 to 3.1101.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1101.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1101.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:53:07 +00:00
GitHub Actions 533ad3f138 chore: Update dist 2026-08-04 03:50:45 +00:00
dependabot[bot] 5a98413048 chore(deps): bump @smithy/node-http-handler from 4.9.12 to 4.9.13 (#1910)
Bumps [@smithy/node-http-handler](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler) from 4.9.12 to 4.9.13.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/node-http-handler/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/node-http-handler@4.9.13/packages/node-http-handler)

---
updated-dependencies:
- dependency-name: "@smithy/node-http-handler"
  dependency-version: 4.9.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:50:18 +00:00
dependabot[bot] 6d65716bae chore(deps-dev): bump @biomejs/biome from 2.5.5 to 2.5.6 (#1909)
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.5 to 2.5.6.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.6/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:48:15 +00:00
GitHub Actions 1d168a55fe chore: Update dist 2026-08-04 03:45:58 +00:00
dependabot[bot] 848d062284 chore(deps): bump ip-address from 10.2.0 to 10.4.0 (#1912)
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:45:29 +00:00
GitHub Actions d3194f48b9 chore: Update dist 2026-08-04 03:44:21 +00:00
dependabot[bot] 61c52b4114 chore(deps-dev): bump @aws-sdk/credential-provider-env (#1907)
Bumps [@aws-sdk/credential-provider-env](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/credential-provider-env) from 3.972.62 to 3.972.65.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-env/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-env)

---
updated-dependencies:
- dependency-name: "@aws-sdk/credential-provider-env"
  dependency-version: 3.972.65
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 03:43:47 +00:00
GitHub Actions 91d3095422 chore: Update dist 2026-07-28 03:56:46 +00:00
dependabot[bot] 43a31ecb43 chore(deps): bump @aws-sdk/client-sts from 3.1091.0 to 3.1096.0 (#1904)
Bumps [@aws-sdk/client-sts](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-sts) from 3.1091.0 to 3.1096.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-sts/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1096.0/clients/client-sts)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-sts"
  dependency-version: 3.1096.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 03:56:10 +00:00
GitHub Actions 13db8f061e chore: Update dist 2026-07-28 03:54:33 +00:00
dependabot[bot] 7b65d1d5f3 chore(deps-dev): bump @aws-sdk/credential-provider-env (#1906)
Bumps [@aws-sdk/credential-provider-env](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/credential-provider-env) from 3.972.59 to 3.972.62.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/credential-provider-env/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/credential-provider-env)

---
updated-dependencies:
- dependency-name: "@aws-sdk/credential-provider-env"
  dependency-version: 3.972.62
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 03:53:58 +00:00
dependabot[bot] 49a3467caa chore(deps-dev): bump @types/node from 26.1.1 to 26.1.2 (#1902)
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.1 to 26.1.2.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 03:51:42 +00:00
dependabot[bot] f0a75f4173 chore(deps-dev): bump @biomejs/biome from 2.5.4 to 2.5.5 (#1905)
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.5.4 to 2.5.5.
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.5/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 03:48:57 +00:00
GitHub Actions 7d3d30aa06 chore: Update dist 2026-07-28 03:47:23 +00:00
dependabot[bot] 544de3bdd1 chore(deps): bump @smithy/node-http-handler from 4.9.8 to 4.9.12 (#1901)
Bumps [@smithy/node-http-handler](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/node-http-handler) from 4.9.8 to 4.9.12.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/node-http-handler/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/node-http-handler@4.9.12/packages/node-http-handler)

---
updated-dependencies:
- dependency-name: "@smithy/node-http-handler"
  dependency-version: 4.9.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 03:46:50 +00:00
GitHub Actions 63142d578f chore: Update dist 2026-07-28 03:44:31 +00:00
dependabot[bot] 33103b67c5 chore(deps-dev): bump @smithy/property-provider from 4.4.11 to 4.4.15 (#1903)
Bumps [@smithy/property-provider](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/property-provider) from 4.4.11 to 4.4.15.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/property-provider/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/property-provider@4.4.15/packages/property-provider)

---
updated-dependencies:
- dependency-name: "@smithy/property-provider"
  dependency-version: 4.4.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-28 03:44:00 +00:00
dependabot[bot] ebff9ed752 chore(deps-dev): bump postcss from 8.5.16 to 8.5.23 (#1900)
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.16 to 8.5.23.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.5.16...8.5.23)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-27 05:28:50 +00:00
GitHub Actions 247bed75ed docs: update README version references to v6.2.3 2026-07-22 18:32:21 +00:00
24 changed files with 4644 additions and 3067 deletions
+1 -1
View File
@@ -15,7 +15,7 @@ jobs:
runs-on: ubuntu-latest
name: Stale issue job
steps:
- uses: aws-actions/stale-issue-cleanup@v6
- uses: aws-actions/stale-issue-cleanup@v7
with:
# Setting messages to an empty string will cause the automation to skip
# that category
+6
View File
@@ -28,6 +28,12 @@ these are incredibly useful:
- Any modifications you've made relevant to the bug
- Anything unusual about your environment or deployment
We also ask that you refrain from opening issues via the `gh` CLI or GitHub
API. These methods bypass our issue templates and therefore don't apply the
proper labels or workflows that we use. Note that AI agents typically do not
properly use issue templates. Issues that don't have the proper labels
applied may be closed without comment.
## Contributing via Pull Requests
Contributions via pull requests are much appreciated. Before sending us a pull
+21 -20
View File
@@ -61,7 +61,7 @@ Authenticate to AWS in GitHub Actions (and others)! Works especially well with
runs-on: ubuntu-latest
steps:
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
role-to-assume: <Role ARN you created in step 2>
aws-region: <AWS Region you want to use>
@@ -250,7 +250,7 @@ specify the profile name as an environment variable in the job step:
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789100:role/my-role
@@ -268,14 +268,14 @@ step environment variables:
```yaml
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789100:role/my-first-role
aws-profile: firstRoleInChain
- name: assume second role
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
@@ -311,7 +311,7 @@ this action will always consider the `HTTP_PROXY` environment variable.
Manually configured proxy:
```yaml
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
role-to-assume: my-github-actions-role
@@ -458,7 +458,7 @@ line.
<summary>Inline session policy examples</summary>
```yaml
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
inline-session-policy: '{"Version":"2012-10-17","Statement":[{"Sid":"Stmt1","Effect":"Allow","Action":"s3:List*","Resource":"*"}]}'
```
@@ -466,7 +466,7 @@ with:
Or we can have a nicely formatted JSON as well:
```yaml
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
inline-session-policy: >-
{
@@ -494,7 +494,7 @@ the role.
<summary>Managed session policy examples</summary>
```yaml
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
managed-session-policies: arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
```
@@ -502,7 +502,7 @@ with:
And we can pass multiple managed policies likes this:
```yaml
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
managed-session-policies: |
arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess
@@ -548,7 +548,7 @@ specify the audience through the `audience` input:
```yaml
- name: Configure AWS Credentials for China region audience
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
audience: sts.amazonaws.com.cn
aws-region: cn-northwest-1
@@ -600,8 +600,9 @@ claims ([1][gh-blog-oidc], [2][sub-claim-custom]).
#### Immutable subject claims
Repositories created on github.com on or after 15 July 2026, and older
repositories that have opted in, emit an [immutable `sub` claim][immutable-sub].
Repositories created on github.com on or after 15 July 2026, older
repositories that have opted in, and older repositories that have been renamed
since 15 July 2026, emit an [immutable `sub` claim][immutable-sub].
This claim appends the permanent numeric ID of the organization and of the
repository after each name, separated by `@`, so that a recycled org or
repository name cannot be used to mint tokens matching a stale trust policy.
@@ -708,7 +709,7 @@ Provider. The audience would still be `sts.amazonaws.com` by default.
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
@@ -724,13 +725,13 @@ environment variable and use it to assume the role
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
role-session-name: MySessionName
- name: Configure other AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::987654321000:role/my-second-role
@@ -752,7 +753,7 @@ alternatively, the `TagSession` permission can be omitted if you are using the
```yaml
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
@@ -773,7 +774,7 @@ like `role-to-assume: my-github-actions-role`.
```yaml
- name: Configure AWS Credentials 1
id: creds
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789100:role/my-github-actions-role
@@ -782,7 +783,7 @@ like `role-to-assume: my-github-actions-role`.
run: |
aws sts get-caller-identity
- name: Configure AWS Credentials 2
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-2
aws-access-key-id: ${{ steps.creds.outputs.aws-access-key-id }}
@@ -813,14 +814,14 @@ provided.
```yaml
- name: Configure AWS Credentials for Dev
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::111111111111:role/dev-role
aws-profile: dev
- name: Configure AWS Credentials for Prod
uses: aws-actions/configure-aws-credentials@v6.1.0
uses: aws-actions/configure-aws-credentials@v6.2.3
with:
aws-region: us-west-2
role-to-assume: arn:aws:iam::222222222222:role/prod-role
+23 -23
View File
@@ -222,7 +222,7 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
The following npm package may be included in this product:
- @aws-sdk/client-sts@3.1091.0
- @aws-sdk/client-sts@3.1116.0
This package contains the following license:
@@ -432,9 +432,9 @@ Apache License
The following npm packages may be included in this product:
- @aws-sdk/signature-v4-multi-region@3.996.41
- @smithy/core@3.29.6
- @smithy/types@4.16.1
- @aws-sdk/signature-v4-multi-region@3.996.46
- @smithy/core@3.33.3
- @smithy/types@4.17.2
These packages each contain the following license:
@@ -832,7 +832,7 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
The following npm package may be included in this product:
- @aws-sdk/core@3.975.3
- @aws-sdk/core@3.977.9
This package contains the following license:
@@ -1042,16 +1042,16 @@ Apache License
The following npm packages may be included in this product:
- @aws-sdk/credential-provider-env@3.972.59
- @aws-sdk/credential-provider-ini@3.973.4
- @aws-sdk/credential-provider-node@3.972.70
- @aws-sdk/token-providers@3.1088.0
- @aws-sdk/types@3.974.2
- @aws-sdk/xml-builder@3.972.36
- @smithy/credential-provider-imds@4.4.11
- @smithy/fetch-http-handler@5.6.8
- @smithy/node-http-handler@4.9.8
- @smithy/signature-v4@5.6.7
- @aws-sdk/credential-provider-env@3.972.70
- @aws-sdk/credential-provider-ini@3.973.15
- @aws-sdk/credential-provider-node@3.972.81
- @aws-sdk/token-providers@3.1116.0
- @aws-sdk/types@3.974.5
- @aws-sdk/xml-builder@3.972.40
- @smithy/credential-provider-imds@4.5.2
- @smithy/fetch-http-handler@5.7.2
- @smithy/node-http-handler@4.11.3
- @smithy/signature-v4@5.6.12
These packages each contain the following license:
@@ -1261,9 +1261,9 @@ Apache License
The following npm packages may be included in this product:
- @aws-sdk/credential-provider-process@3.972.59
- @aws-sdk/credential-provider-sso@3.973.3
- @aws-sdk/credential-provider-web-identity@3.972.65
- @aws-sdk/credential-provider-process@3.972.70
- @aws-sdk/credential-provider-sso@3.973.14
- @aws-sdk/credential-provider-web-identity@3.972.76
These packages each contain the following license:
@@ -1473,9 +1473,9 @@ Apache License
The following npm packages may be included in this product:
- @aws-sdk/credential-provider-http@3.972.61
- @aws-sdk/credential-provider-login@3.972.66
- @aws-sdk/nested-clients@3.997.33
- @aws-sdk/credential-provider-http@3.972.72
- @aws-sdk/credential-provider-login@3.972.77
- @aws-sdk/nested-clients@3.997.44
These packages each contain the following license:
@@ -1485,7 +1485,7 @@ Apache-2.0
The following npm package may be included in this product:
- ip-address@10.2.0
- ip-address@10.4.0
This package contains the following license:
@@ -1740,7 +1740,7 @@ SOFTWARE.
The following npm package may be included in this product:
- undici@6.27.0
- undici@6.28.0
This package contains the following license:
Generated Vendored
+88 -6
View File
@@ -1929,7 +1929,11 @@ var require_request = __commonJS({
} else if (typeof val[i] === "object") {
throw new InvalidArgumentError(`invalid ${key} header`);
} else {
arr.push(`${val[i]}`);
const str = `${val[i]}`;
if (!isValidHeaderValue(str)) {
throw new InvalidArgumentError(`invalid ${key} header`);
}
arr.push(str);
}
}
val = arr;
@@ -1941,6 +1945,9 @@ var require_request = __commonJS({
val = "";
} else {
val = `${val}`;
if (!isValidHeaderValue(val)) {
throw new InvalidArgumentError(`invalid ${key} header`);
}
}
if (headerName === "host") {
if (request.host !== null) {
@@ -5671,6 +5678,7 @@ var require_client_h1 = __commonJS({
RequestContentLengthMismatchError,
ResponseContentLengthMismatchError,
RequestAbortedError,
InvalidArgumentError,
HeadersTimeoutError,
HeadersOverflowError,
SocketError,
@@ -6397,8 +6405,16 @@ var require_client_h1 = __commonJS({
}
body = bodyStream.stream;
contentLength = bodyStream.length;
} else if (util.isBlobLike(body) && request.contentType == null && body.type) {
headers.push("content-type", body.type);
} else if (util.isBlobLike(body) && request.contentType == null) {
const contentType = body.type;
if (contentType) {
const contentTypeValue = `${contentType}`;
if (!util.isValidHeaderValue(contentTypeValue)) {
util.errorRequest(client, request, new InvalidArgumentError("invalid content-type header"));
return false;
}
headers.push("content-type", contentTypeValue);
}
}
if (body && typeof body.read === "function") {
body.read(0);
@@ -8950,6 +8966,24 @@ var require_retry_handler = __commonJS({
const current = Date.now();
return new Date(retryAfter).getTime() - current;
}
function validatePartialResponseContentLength(headers, range, statusCode, retryCount) {
const contentLength = headers["content-length"];
if (contentLength == null) {
return null;
}
if (!Number.isFinite(range.start) || !Number.isFinite(range.end)) {
return null;
}
const length = Number(contentLength);
const expectedLength = range.end - range.start + 1;
if (!Number.isFinite(length) || length !== expectedLength) {
return new RequestRetryError("Content-Length mismatch", statusCode, {
headers,
data: { count: retryCount }
});
}
return null;
}
var RetryHandler = class _RetryHandler {
constructor(opts, handlers) {
const { retryOptions, ...dispatchOpts } = opts;
@@ -9122,6 +9156,11 @@ var require_retry_handler = __commonJS({
);
return false;
}
const contentLengthError = validatePartialResponseContentLength(headers, contentRange, statusCode, this.retryCount);
if (contentLengthError != null) {
this.abort(contentLengthError);
return false;
}
const { start, size, end = size - 1 } = contentRange;
assert(this.start === start, "content-range mismatch");
assert(this.end == null || this.end === end, "content-range mismatch");
@@ -9139,6 +9178,11 @@ var require_retry_handler = __commonJS({
statusMessage
);
}
const contentLengthError = validatePartialResponseContentLength(headers, range, statusCode, this.retryCount);
if (contentLengthError != null) {
this.abort(contentLengthError);
return false;
}
const { start, size, end = size - 1 } = range;
assert(
start != null && Number.isFinite(start),
@@ -15984,14 +16028,48 @@ var require_util6 = __commonJS({
for (let i = 0; i < path.length; ++i) {
const code = path.charCodeAt(i);
if (code < 32 || // exclude CTLs (0-31)
code === 127 || // DEL
code > 126 || // exclude DEL and non-ascii
code === 59) {
throw new Error("Invalid cookie path");
}
}
}
function isLetterOrDigit(code) {
return code >= 48 && code <= 57 || // 0-9
code >= 65 && code <= 90 || // A-Z
code >= 97 && code <= 122;
}
function validateCookieDomain(domain) {
if (domain.startsWith("-") || domain.endsWith(".") || domain.endsWith("-")) {
if (domain === " ") {
return;
}
if (domain.length > 255) {
throw new Error("Invalid cookie domain");
}
let labelLength = 0;
for (let i = 0; i < domain.length; ++i) {
const code = domain.charCodeAt(i);
if (code === 46) {
if (labelLength === 0) {
throw new Error("Invalid cookie domain");
}
if (domain.charCodeAt(i - 1) === 45) {
throw new Error("Invalid cookie domain");
}
labelLength = 0;
continue;
}
if (labelLength === 0 && !isLetterOrDigit(code)) {
throw new Error("Invalid cookie domain");
}
if (!isLetterOrDigit(code) && code !== 45) {
throw new Error("Invalid cookie domain");
}
if (++labelLength > 63) {
throw new Error("Invalid cookie domain");
}
}
if (labelLength === 0 || domain.charCodeAt(domain.length - 1) === 45) {
throw new Error("Invalid cookie domain");
}
}
@@ -16074,7 +16152,11 @@ var require_util6 = __commonJS({
throw new Error("Invalid unparsed");
}
const [key, ...value] = part.split("=");
out.push(`${key.trim()}=${value.join("=")}`);
const trimmedKey = key.trim();
const joinedValue = value.join("=");
validateCookieName(trimmedKey);
validateCookieValue(joinedValue);
out.push(`${trimmedKey}=${joinedValue}`);
}
return out.join("; ");
}
Generated Vendored
+3901 -2210
View File
File diff suppressed because it is too large Load Diff
-14
View File
@@ -1,14 +0,0 @@
# Examples
## [federated-setup](./federated-setup/README.md)
The directory contains templates for setting up the `configure-aws-credentials`
federation between your GitHub Organization/repository and your AWS account.
## [cfn-deploy-example](./cfn-deploy-example/README.md)
Repository example uses aws-action `configure-aws-credentials` with OIDC
federation template
[github-actions-oidc-federation-and-role](./github-actions-oidc-federation-and-role.yml).
Example demonstrates a repository that deploys AWS CloudFormation template using
cfn-deploy GitHub Action.
@@ -1,15 +0,0 @@
name: 'compliance'
## run ci testing on all push events
on: [push]
jobs:
## Guard rule set
sast-guard:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: grolston/guard-action@main
with:
data_directory: './cloudformation/' ## change to your template directory
rule_set: 'FedRAMP-Moderate'
show_summary: 'all'
output_format: 'single-line-summary'
@@ -1,38 +0,0 @@
---
name: deploy
on:
push:
branches:
- main
env:
AWS_DEFAULT_REGION: us-east-1
AWS_DEFAULT_OUTPUT: json
jobs:
deploy-cfn:
name: deploy
runs-on: ubuntu-latest
# These permissions are needed to interact with GitHubs OIDC Token endpoint.
permissions:
id-token: write
contents: read
steps:
- name: Checkout
uses: actions/checkout@v5
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6
with:
aws-region: us-east-1
## the following creates an ARN based on the values entered into github secrets
role-to-assume: arn:aws:iam::${{ secrets.AWS_ACCOUNT_ID }}:role/${{ secrets.AWS_DEPLOY_ROLE }}
role-session-name: myGitHubActions
- name: Deploy EC2 Bastion
uses: aws-actions/aws-cloudformation-github-deploy@v1.3.0
with:
name: myEC2bastion
## change to path to template in your github repo
template: cloudformation/ec2-bastion.yml
capabilities: CAPABILITY_IAM, CAPABILITY_NAMED_IAM
no-fail-on-empty-changeset: "1"
## parameter set in github secrets
parameter-overrides: "pVpc=${{ secrets.VPC_ID }},pSubnet=${{ secrets.SUBNET_ID }}"
-24
View File
@@ -1,24 +0,0 @@
# cfn-deploy example
Example uses aws-action `configure-aws-credentials` with OIDC federation. Prior
to using this example project, the user needs to deploy the
[github-actions-oidc-federation-and-role](../federated-setup/github-actions-oidc-federation-and-role.yml)
template in the AWS account they want to deploy the CloudFormation template
into. Specify the GitHub Organization name, repository name, and the specific
branch you want to deploy on.
Within the [github/workflows](./.github/workflows/) directory there is a
[compliance.yml](./.github/workflows/compliance.yml) and a
[deploy.yml](./.github/workflows/deploy.yml). The deploy.yml file leverages the
aws-action `configure-aws-credentials` and accesses GitHub Action Secrets for
some of the variables. The compliance.yml runs static application security
testing using cfn-guard.
To use the example you will need to set the following GitHub Action Secrets:
| Secret Key | Used With | Description |
| --------------- | -------------------------------- | ---------------------------------------- |
| AWS_ACCOUNT_ID | configure-aws-credentials | The AWS account ID |
| AWS_DEPLOY_ROLE | configure-aws-credentials | The name of the IAM role |
| VPC_ID | aws-cloudformation-github-deploy | VPC ID the EC2 Bastion is deployed to |
| SUBNET_ID | aws-cloudformation-github-deploy | Subnet ID the EC2 Bastion is deployed to |
-150
View File
@@ -1,150 +0,0 @@
---
AWSTemplateFormatVersion: "2010-09-09"
Description: EC2 bastion for latest AWS Linux 2 EC2 deployment
Metadata:
AWS::CloudFormation::Interface:
ParameterGroups:
- Label:
default: "EC2 Configuration"
Parameters:
- pTagNameValue
- pOperatingSystem
- pInstanceType
- pVolumeSize
- pEbsDeleteOnTermination
- Label:
default: "Network Configuration"
Parameters:
- pVpc
- pSubnet
ParameterLabels:
pOperatingSystem:
default: "Operating System"
pInstanceType:
default: "Instance Type"
pTagNameValue:
default: "EC2 Name"
pVolumeSize:
default: "Volume Size"
pEbsDeleteOnTermination:
default: "Delete EBS Volume on Termination"
pSubnet:
default: "Subnet"
pVpc:
default: "VPC"
Parameters:
pSubnet:
Description: The subnet to launch the instance in to. It must be part of the VPC chosen above.
Type: AWS::EC2::Subnet::Id
pVpc:
Description: The VPC to launch the EC2 instance in to.
Type: AWS::EC2::VPC::Id
pOperatingSystem:
Type: "AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>"
Default: "/aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-ebs"
pInstanceType:
Description: Desired Instance Size
Type: String
Default: t3.small
AllowedValues:
- t3.small
- t3.medium
- t3.nano
pTagNameValue:
Description: "Required: Enter the tag name you'd like applied to the instance. Tag Name gives the name to the EC2 instance."
Type: String
MinLength: 1
Default: "myBastion"
pVolumeSize:
Description:
Enter the number of GBs you want your volume to be. The minimum value
is 8 GBs
Type: Number
Default: 50
MinValue: 8
pEbsDeleteOnTermination:
Description: "Specify if the EBS volume should be deleted if EC2 is deleted."
Type: String
Default: true
AllowedValues:
- true
- false
Rules:
SubnetInVPC:
Assertions:
- Assert: !EachMemberIn
- !ValueOfAll
- AWS::EC2::Subnet::Id
- VpcId
- !RefAll "AWS::EC2::VPC::Id"
AssertDescription: All subnets must in the VPC
Resources:
rSecurityGroupDefault:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: !Sub "Default SG for SC Product ${pTagNameValue} "
VpcId: !Ref pVpc
SecurityGroupEgress:
- Description: Outbound unrestricted traffic
IpProtocol: "-1"
CidrIp: 0.0.0.0/0
Tags:
- Key: Name
Value: !Ref pTagNameValue
rLinuxEc2:
Type: AWS::EC2::Instance
Metadata:
guard:
SuppressedRules:
- 'EC2_INSTANCE_DETAILED_MONITORING_ENABLED'
Properties:
ImageId: !Ref pOperatingSystem
IamInstanceProfile: !Ref rec2InstanceProfile
Monitoring: false
InstanceType: !Ref pInstanceType
EbsOptimized: true
SourceDestCheck: true
SubnetId: !Ref pSubnet
SecurityGroupIds:
- !Ref rSecurityGroupDefault
BlockDeviceMappings:
- DeviceName: "/dev/xvda"
Ebs:
VolumeSize: !Ref pVolumeSize
DeleteOnTermination: !Ref pEbsDeleteOnTermination
Tags:
- Key: Name
Value: !Ref pTagNameValue
UserData:
Fn::Base64:
yum update -y
## Instance Profiles
## EC2 IAM Roles
rEc2Role:
Type: AWS::IAM::Role
Properties:
RoleName: !Sub "ec2-role-${AWS::StackName}"
AssumeRolePolicyDocument:
Statement:
- Effect: Allow
Principal:
Service: [ec2.amazonaws.com]
Action: ['sts:AssumeRole']
Path: /
ManagedPolicyArns:
- !Sub 'arn:${AWS::Partition}:iam::aws:policy/AmazonSSMManagedInstanceCore'
- !Sub 'arn:${AWS::Partition}:iam::aws:policy/CloudWatchAgentServerPolicy'
rec2InstanceProfile:
Type: AWS::IAM::InstanceProfile
Properties:
InstanceProfileName: !Sub "ec2-profile-${AWS::StackName}"
Path: /
Roles:
- !Ref rEc2Role
Outputs:
oLinuxEc2InstanceId:
Description: Resource ID of the newly created EC2 instance
Value: !Ref rLinuxEc2
oLinuxEc2PrivateIP:
Description: Private IP Address for EC2
Value: !GetAtt rLinuxEc2.PrivateIp
-11
View File
@@ -1,11 +0,0 @@
# federated-setup
## [github-action-oidc-federation](./github-actions-oidc-federation.yml)
Setup of the OIDC federation between your GitHub Organization/repository and
your AWS account.
## [github-actions-oidc-federation-and-role](./github-actions-oidc-federation-and-role.yml)
Setup of the OIDC federation between your GitHub Organization/repository and
your AWS account along with a role that only executes on specific branch.
@@ -1,82 +0,0 @@
---
AWSTemplateFormatVersion: "2010-09-09"
Description: Github Actions configuration - OIDC IAM IdP and associated role CI/CD
Parameters:
GitHubOrganization:
Type: String
Description: This is the root organization or personal account where repos are stored (Case Sensitive)
RepositoryName:
Type: String
Description: The repo(s) these roles will have access to. (Use * for all org or personal repos)
Default: "*"
BranchName:
Type: String
Description: Name of the git branch to to trust. (Use * for all branches)
Default: "*"
RoleName:
Type: String
Description: Name the Role
UseExistingProvider:
Type: String
Description: "Only one GitHub Provider can exists. Choose yes if one is already present in account"
Default: "no"
AllowedValues:
- "yes"
- "no"
Conditions:
CreateProvider: !Equals ["no", !Ref UseExistingProvider]
Resources:
IdpGitHubOidc:
Type: AWS::IAM::OIDCProvider
Condition: CreateProvider
Properties:
Url: https://token.actions.githubusercontent.com
ClientIdList:
- sts.amazonaws.com
- !Sub https://github.com/${GitHubOrganization}/${RepositoryName}
ThumbprintList:
- 6938fd4d98bab03faadb97b34396831e3780aea1
Tags:
- Key: Name
Value: !Sub ${RoleName}-OIDC-Provider
RoleGithubActions:
Type: AWS::IAM::Role
Properties:
RoleName: !Ref RoleName
AssumeRolePolicyDocument:
Statement:
- Effect: Allow
Action: sts:AssumeRoleWithWebIdentity
Principal:
Federated: !If
- CreateProvider
- !Ref IdpGitHubOidc
- !Sub arn:${AWS::Partition}:iam::${AWS::AccountId}:oidc-provider/token.actions.githubusercontent.com
Condition:
StringLike:
token.actions.githubusercontent.com:sub: !Sub repo:${GitHubOrganization}/${RepositoryName}:ref:refs/heads/${BranchName}
ManagedPolicyArns:
## edit the managed policy to give least privileges
- !Sub arn:${AWS::Partition}:iam::aws:policy/AdministratorAccess
Outputs:
IdpGitHubOidc:
Condition: CreateProvider
Description: "ARN of Github OIDC Provider"
Value: !GetAtt IdpGitHubOidc.Arn
RoleGithubActionsARN:
Description: "CICD Role for GitHub Actions"
Value: !GetAtt RoleGithubActions.Arn
@@ -1,43 +0,0 @@
---
AWSTemplateFormatVersion: "2010-09-09"
Description: Github Actions configuration - OIDC IAM IdP Federation
Parameters:
GitHubOrganization:
Type: String
Description: This is the root organization or personal account where repos are stored (Case Sensitive)
Default: ""
RepositoryName:
Type: String
Description: The repo(s) these roles will have access to. (Use * for all org or personal repos)
Default: "*"
RoleName:
Type: String
Description: Name the Role
Default: ""
Resources:
IdpGitHubOidc:
Type: AWS::IAM::OIDCProvider
Properties:
Url: https://token.actions.githubusercontent.com
ClientIdList:
- sts.amazonaws.com
- !Sub https://github.com/${GitHubOrganization}/${RepositoryName}
ThumbprintList:
- 6938fd4d98bab03faadb97b34396831e3780aea1
Tags:
- Key: Name
Value: !Sub ${RoleName}-OIDC-Provider
Outputs:
IdpGitHubOidc:
Description: "ARN of Github OIDC Provider"
Value: !GetAtt IdpGitHubOidc.Arn
+382 -384
View File
File diff suppressed because it is too large Load Diff
+9 -8
View File
@@ -17,25 +17,26 @@
"organization": true
},
"devDependencies": {
"@aws-sdk/credential-provider-env": "^3.972.59",
"@biomejs/biome": "2.5.4",
"@smithy/property-provider": "^4.4.11",
"@types/node": "^26.1.1",
"@aws-sdk/credential-provider-env": "^3.972.70",
"@biomejs/biome": "2.5.10",
"@smithy/property-provider": "^4.5.2",
"@types/node": "^26.2.0",
"@vitest/coverage-v8": "4.1.10",
"aws-sdk-client-mock": "^4.1.0",
"esbuild": "^0.28.1",
"esbuild": "^0.28.2",
"generate-license-file": "^4.2.1",
"json-schema": "^0.4.0",
"markdownlint-cli": "^0.49.1",
"memfs": "^4.64.0",
"memfs": "^4.68.1",
"standard-version": "^9.5.0",
"typescript": "^7.0.2",
"vitest": "4.1.10"
},
"dependencies": {
"@actions/core": "^3.0.1",
"@aws-sdk/client-sts": "^3.1091.0",
"@smithy/node-http-handler": "^4.9.8",
"@aws-sdk/client-sts": "^3.1116.0",
"@aws-sdk/credential-provider-node": "^3.972.63",
"@smithy/node-http-handler": "^4.11.3",
"proxy-agent": "^8.0.2"
},
"keywords": [
+13 -5
View File
@@ -1,9 +1,10 @@
import { info } from '@actions/core';
import { STSClient } from '@aws-sdk/client-sts';
import { defaultProvider } from '@aws-sdk/credential-provider-node';
import type { AwsCredentialIdentity } from '@aws-sdk/types';
import { NodeHttpHandler } from '@smithy/node-http-handler';
import { ProxyAgent } from 'proxy-agent';
import { buildCustomUserAgent, errorMessage, getCallerIdentity } from './helpers';
import { buildCustomUserAgent, errorMessage, getCallerIdentity, maskProxyCredentials } from './helpers';
import { ProxyResolver } from './ProxyResolver';
if (!process.env.AWS_EXECUTION_ENV) {
@@ -31,6 +32,7 @@ export class CredentialsClient {
}
if (props.proxyServer) {
info('Configuring proxy handler for STS client');
maskProxyCredentials(props.proxyServer);
const proxyOptions: { httpProxy: string; httpsProxy: string; noProxy?: string } = {
httpProxy: props.proxyServer,
httpsProxy: props.proxyServer,
@@ -105,9 +107,15 @@ export class CredentialsClient {
}
private async loadCredentials() {
const config = {} as { requestHandler?: NodeHttpHandler };
if (this.requestHandler !== undefined) config.requestHandler = this.requestHandler;
const client = new STSClient(config);
return client.config.credentials();
// Previously we constructed a new client, but that picks up the default provider chain including the endpoint.
// Explicitly calling the default provider chain allows us to pass in the endpoint and region as well as the
// proxy config.
return defaultProvider({
clientConfig: {
...(this.region !== undefined && { region: this.region }),
...(this.stsEndpoint !== undefined && { endpoint: this.stsEndpoint }),
...(this.requestHandler !== undefined && { requestHandler: this.requestHandler }),
},
})();
}
}
+30 -23
View File
@@ -5,7 +5,6 @@ import type { Credentials, STSClient } from '@aws-sdk/client-sts';
import { GetCallerIdentityCommand } from '@aws-sdk/client-sts';
import type { AwsCredentialIdentity } from '@aws-sdk/types';
import type { UserAgent } from '@smithy/types';
import type { CredentialsClient } from './CredentialsClient';
const MAX_TAG_VALUE_LENGTH = 256;
const SANITIZATION_CHARACTER = '_';
@@ -167,15 +166,13 @@ export function exportAccountId(identity: { Account: string; Arn: string }, mask
// Validates that the account of the already-resolved caller identity is in the allow-list provided via the
// `allowed-account-ids` input.
export function validateAccountId(expectedAccountIds: string[] | undefined, account: string | undefined): void {
if (!expectedAccountIds || expectedAccountIds.length === 0 || expectedAccountIds[0] === '') {
const allowedAccountIds = expectedAccountIds?.filter((id) => id !== '') ?? [];
if (allowedAccountIds.length === 0) {
return;
}
if (!account || !expectedAccountIds.includes(account)) {
throw new Error(
`The account ID of the provided credentials (${
account ?? 'unknown'
}) does not match any of the expected account IDs: ${expectedAccountIds.join(', ')}`,
);
if (!account || !allowedAccountIds.includes(account)) {
// Account IDs are deliberately omitted: this error reaches the job log before any mask exists.
throw new Error('The account ID of the provided credentials does not match any of the allowed account IDs');
}
}
@@ -193,6 +190,29 @@ export function toCredentialIdentity(creds?: Partial<Credentials>): AwsCredentia
};
}
// Registers any userinfo embedded in a proxy URL as secrets so it is masked in job logs.
// First the literal proxy string, then any username/password components if parseable.
// If the username/password is percent-encoded, the decoded form is also masked.
export function maskProxyCredentials(proxyServer: string): void {
core.setSecret(proxyServer);
let url: URL;
try {
url = new URL(proxyServer);
} catch (_) {
return;
}
for (const part of [url.username, url.password]) {
if (!part) continue;
core.setSecret(part);
try {
const decoded = decodeURIComponent(part);
if (decoded !== part) core.setSecret(decoded);
} catch (_) {
// malformed percent-encoding; the raw form is already masked
}
}
}
// Tags have a more restrictive set of acceptable characters than GitHub environment variables can.
// This replaces anything not conforming to the tag restrictions by inverting the regular expression.
// See the AWS documentation for constraint specifics https://docs.aws.amazon.com/STS/latest/APIReference/API_Tag.html.
@@ -260,13 +280,13 @@ export async function retryAndBackoff<T>(
`Retrying after ${Math.floor(delay)}ms.`,
);
await sleep(delay);
if (nextRetry >= maxRetries) {
core.info(`Retry${opName}: reached max retries (${maxRetries}); giving up.`);
throw err;
}
await sleep(delay);
return await retryAndBackoff(fn, isRetryable, maxRetries, nextRetry, base, label);
}
}
@@ -281,19 +301,6 @@ export function isDefined<T>(i: T | undefined | null): i is T {
}
/* c8 ignore stop */
export async function areCredentialsValid(credentialsClient: CredentialsClient) {
const client = credentialsClient.stsClient;
try {
const identity = await client.send(new GetCallerIdentityCommand({}));
if (identity.Account) {
return true;
}
return false;
} catch (_) {
return false;
}
}
/**
* Like core.getBooleanInput, but respects the required option.
*
+13 -5
View File
@@ -3,12 +3,12 @@ import type { AssumeRoleCommandOutput } from '@aws-sdk/client-sts';
import { assumeRole } from './assumeRole';
import { CredentialsClient } from './CredentialsClient';
import {
areCredentialsValid,
errorMessage,
exportAccountId,
exportCredentials,
exportRegion,
getBooleanInput,
getCallerIdentity,
retryAndBackoff,
toCredentialIdentity,
translateEnvVariables,
@@ -53,8 +53,8 @@ export async function run() {
});
const roleChaining = getBooleanInput('role-chaining', { required: false });
const outputCredentials = getBooleanInput('output-credentials', { required: false });
// Default to always outputting environment credentials unless profile is specified. If profile is specified, default
// to no environment credentials (but still output them if the user specifically requests it).
// Default to always outputting environment credentials unless profile is specified. If profile is specified,
// default to no environment credentials (but still output them if the user specifically requests it).
const outputEnvCredentials = getBooleanInput('output-env-credentials', { required: false, default: !awsProfile });
const unsetCurrentCredentials = getBooleanInput('unset-current-credentials', { required: false });
let disableRetry = getBooleanInput('disable-retry', { required: false });
@@ -165,8 +165,16 @@ export async function run() {
//if the user wants to attempt to use existing credentials, check if we have some already
if (useExistingCredentials) {
const validCredentials = await areCredentialsValid(credentialsClient);
if (validCredentials) {
const identity = await (async () => {
try {
return await getCallerIdentity(credentialsClient.stsClient);
} catch {
return null;
}
})();
if (identity) {
// The allowed-account-ids guardrail applies to reused credentials too.
validateAccountId(expectedAccountIds, identity.Account);
core.notice('Pre-existing credentials are valid. No need to generate new ones.');
if (timeoutId) clearTimeout(timeoutId);
return;
+7
View File
@@ -53,8 +53,15 @@ export function parseIni(iniData: string): Record<string, Record<string, string>
export function stringifyIni(data: Record<string, Record<string, string>>): string {
const sections: string[] = [];
for (const [sectionName, sectionData] of Object.entries(data)) {
if (/[\r\n]/.test(sectionName)) {
throw new Error('INI section names must not contain newline characters');
}
const lines: string[] = [`[${sectionName}]`];
for (const [key, value] of Object.entries(sectionData)) {
// A newline in a key or value would inject arbitrary INI lines (e.g. credential_process).
if (/[\r\n]/.test(key) || /[\r\n]/.test(value)) {
throw new Error('INI keys and values must not contain newline characters');
}
lines.push(`${key} = ${value}`);
}
sections.push(lines.join('\n'));
+30
View File
@@ -0,0 +1,30 @@
import { describe, expect, it, vi } from 'vitest';
vi.mock('@aws-sdk/credential-provider-node', () => ({
defaultProvider: vi.fn(() => async () => ({ accessKeyId: 'AKIA', secretAccessKey: 'secret' })),
}));
import { defaultProvider } from '@aws-sdk/credential-provider-node';
import { CredentialsClient } from '../src/CredentialsClient';
describe('CredentialsClient', {}, () => {
it('pins ambient credential resolution to the configured region and STS endpoint', {}, async () => {
const client = new CredentialsClient({
region: 'eu-west-1',
stsEndpoint: 'https://sts.example.com',
roleChaining: false,
});
// biome-ignore lint/suspicious/noExplicitAny: any required to call private method
await (client as any).loadCredentials();
expect(defaultProvider).toHaveBeenCalledWith({
clientConfig: expect.objectContaining({ region: 'eu-west-1', endpoint: 'https://sts.example.com' }),
});
});
it('omits unset client config values from ambient credential resolution', {}, async () => {
const client = new CredentialsClient({ region: 'eu-west-1', roleChaining: false });
// biome-ignore lint/suspicious/noExplicitAny: any required to call private method
await (client as any).loadCredentials();
expect(defaultProvider).toHaveBeenLastCalledWith({ clientConfig: { region: 'eu-west-1' } });
});
});
+39
View File
@@ -126,6 +126,45 @@ describe('Configure AWS Credentials helpers', {}, () => {
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', '');
});
describe('maskProxyCredentials', {}, () => {
it('masks username and password embedded in a proxy URL', {}, () => {
helpers.maskProxyCredentials('http://user:secretpass@proxy.example.com:8080');
expect(core.setSecret).toHaveBeenCalledWith('user');
expect(core.setSecret).toHaveBeenCalledWith('secretpass');
});
it('masks both encoded and decoded forms of the credentials', {}, () => {
helpers.maskProxyCredentials('http://user:p%40ss@proxy.example.com:8080');
expect(core.setSecret).toHaveBeenCalledWith('p%40ss');
expect(core.setSecret).toHaveBeenCalledWith('p@ss');
});
it('masks the whole value even without embedded credentials or when unparseable', {}, () => {
helpers.maskProxyCredentials('http://proxy.example.com:8080');
expect(core.setSecret).toHaveBeenCalledWith('http://proxy.example.com:8080');
helpers.maskProxyCredentials('not a url');
expect(core.setSecret).toHaveBeenCalledWith('not a url');
// no username/password parts, so exactly one mask per call
expect(core.setSecret).toHaveBeenCalledTimes(2);
});
});
describe('validateAccountId', {}, () => {
it('enforces the allow-list even when the first element is empty', {}, () => {
expect(() => helpers.validateAccountId(['', '999999999999'], '111111111111')).toThrow(/does not match/);
});
it('passes an allowed account despite empty entries in the list', {}, () => {
expect(() => helpers.validateAccountId(['', '111111111111'], '111111111111')).not.toThrow();
});
it('skips validation only when no non-empty entries exist', {}, () => {
expect(() => helpers.validateAccountId(undefined, '111111111111')).not.toThrow();
expect(() => helpers.validateAccountId([], '111111111111')).not.toThrow();
expect(() => helpers.validateAccountId([''], '111111111111')).not.toThrow();
});
});
describe('filesystem helpers', {}, () => {
describe('isSymlink', {}, () => {
it('returns true for a symlink', {}, () => {
+47 -5
View File
@@ -841,7 +841,7 @@ describe('Configure AWS Credentials', {}, () => {
await run();
expect(core.setFailed).toHaveBeenCalledWith(
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
'The account ID of the provided credentials does not match any of the allowed account IDs',
);
});
@@ -861,7 +861,7 @@ describe('Configure AWS Credentials', {}, () => {
await run();
expect(core.setFailed).toHaveBeenCalledWith(
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999, 888888888888',
'The account ID of the provided credentials does not match any of the allowed account IDs',
);
});
@@ -917,7 +917,7 @@ describe('Configure AWS Credentials', {}, () => {
await run();
expect(core.setFailed).toHaveBeenCalledWith(
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
'The account ID of the provided credentials does not match any of the allowed account IDs',
);
});
@@ -936,7 +936,7 @@ describe('Configure AWS Credentials', {}, () => {
await run();
expect(core.setFailed).toHaveBeenCalledWith(
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
'The account ID of the provided credentials does not match any of the allowed account IDs',
);
});
@@ -956,7 +956,7 @@ describe('Configure AWS Credentials', {}, () => {
await run();
expect(core.setFailed).toHaveBeenCalledWith(
'The account ID of the provided credentials (111111111111) does not match any of the expected account IDs: 999999999999',
'The account ID of the provided credentials does not match any of the allowed account IDs',
);
});
@@ -1015,6 +1015,33 @@ describe('Configure AWS Credentials', {}, () => {
await run();
expect(core.setFailed).not.toHaveBeenCalled();
});
it('fails on the use-existing-credentials path when the account is not allowed', async () => {
vi.mocked(core.getInput).mockImplementation(
mocks.getInput({
...mocks.USE_EXISTING_CREDENTIALS_INPUTS,
'allowed-account-ids': '999999999999',
}),
);
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
await run();
expect(core.setFailed).toHaveBeenCalledWith(expect.stringContaining('does not match'));
});
it('reuses existing credentials when their account is allowed', async () => {
vi.mocked(core.getInput).mockImplementation(
mocks.getInput({
...mocks.USE_EXISTING_CREDENTIALS_INPUTS,
'allowed-account-ids': '111111111111',
}),
);
mockedSTSClient.on(GetCallerIdentityCommand).resolves({ ...mocks.outputs.GET_CALLER_IDENTITY });
await run();
expect(core.notice).toHaveBeenCalledWith('Pre-existing credentials are valid. No need to generate new ones.');
expect(core.setFailed).not.toHaveBeenCalled();
});
});
describe('Global Timeout Configuration', {}, () => {
@@ -1240,6 +1267,21 @@ describe('Configure AWS Credentials', {}, () => {
expect(core.setFailed).not.toHaveBeenCalled();
});
it('masks credentials embedded in the proxy URL', async () => {
vi.mocked(core.getInput).mockImplementation(
mocks.getInput({
...mocks.GH_OIDC_INPUTS,
'http-proxy': 'http://user:secretpass@proxy.example.com:8080',
}),
);
await run();
expect(core.setSecret).toHaveBeenCalledWith('user');
expect(core.setSecret).toHaveBeenCalledWith('secretpass');
expect(core.setFailed).not.toHaveBeenCalled();
});
});
describe('AWS Profile Support', {}, () => {
+34
View File
@@ -114,6 +114,22 @@ describe('Profile Manager', {}, () => {
const result = stringifyIni({ dev: {} });
expect(result).toBe('[dev]\n');
});
it('rejects values containing newlines', {}, () => {
expect(() =>
stringifyIni({ dev: { aws_session_token: 'token\n[injected]\ncredential_process = evil' } }),
).toThrow('must not contain newline characters');
});
it('rejects keys containing newlines', {}, () => {
expect(() => stringifyIni({ dev: { 'key\ninjected': 'val' } })).toThrow('must not contain newline characters');
});
it('rejects section names containing newlines', {}, () => {
expect(() => stringifyIni({ 'dev\r\n[injected]': { key: 'val' } })).toThrow(
'must not contain newline characters',
);
});
});
describe('validateProfileName', {}, () => {
@@ -423,6 +439,24 @@ describe('Profile Manager', {}, () => {
expect(configParsed['profile dev'].region).toBe('us-east-1');
});
it('refuses to write credentials containing newlines instead of injecting profiles', {}, () => {
expect(() =>
writeProfileFiles(
'dev',
{
AccessKeyId: 'AKIAIOSFODNN7EXAMPLE',
SecretAccessKey: 'wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY',
SessionToken: 'token\n[injected]\ncredential_process = evil-command',
},
'us-east-1',
false,
),
).toThrow('must not contain newline characters');
const credsPath = getProfileFilePaths().credentials;
expect(fs.existsSync(credsPath)).toBe(false);
});
it('uses correct section naming for default profile', {}, () => {
writeProfileFiles(
'default',