Skip to content

chore: pin re-usable actions to released version#1375

Merged
Ron (rjaegers) merged 3 commits into
mainfrom
chore/pin-to-released-actions
Jul 23, 2026
Merged

chore: pin re-usable actions to released version#1375
Ron (rjaegers) merged 3 commits into
mainfrom
chore/pin-to-released-actions

Conversation

@rjaegers

@rjaegers Ron (rjaegers) commented Jul 22, 2026

Copy link
Copy Markdown
Member

🚀 Hey, I have created a Pull Request

Description of changes

This pull request updates several GitHub workflow files to use a new version (actions/v1.1.0) of shared GitHub Actions from the philips-software/amp-devcontainer repository, instead of referencing local actions or older commit SHAs. Additionally, it changes the tag separator for the actions package in release-please-config.json to a slash (/). These changes help ensure consistency and maintainability by centralizing action management and aligning with the latest release practices.

Workflow action updates:

  • Updated .github/workflows/update-dependencies.yml to use the update-apt-packages and update-vscode-extensions actions from philips-software/amp-devcontainer@actions/v1.1.0 instead of local actions. [1] [2]
  • Updated .github/workflows/wc-build-push.yml to use the following actions from philips-software/amp-devcontainer@actions/v1.1.0: merge-devcontainer-metadata, container-size-diff, and generate-tool-inventory. [1] [2] [3]

Release configuration:

  • Changed the tag-separator for the actions package in release-please-config.json from - to / to match the new release tagging convention.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM
  • I understand the image size delta and agree the functionality justifies it

@rjaegers
Ron (rjaegers) requested a review from a team as a code owner July 22, 2026 08:20
Copilot AI review requested due to automatic review settings July 22, 2026 08:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the wc-build-push reusable workflow to pin the repository’s own composite actions to the released v8.0.1 commit SHA, improving stability/reproducibility of CI runs while keeping action references immutable.

Changes:

  • Pin merge-devcontainer-metadata action to v8.0.1 (commit bd6e32c...).
  • Pin container-size-diff action to v8.0.1 (commit bd6e32c...).
  • Pin generate-tool-inventory action to v8.0.1 (commit bd6e32c...).

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1375

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 75.35 MB 75.35 MB 842 B (0%) 🔽
linux/arm64 73.43 MB 73.43 MB 873 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Test Results

 25 files  ±0   25 suites  ±0   20m 8s ⏱️ +45s
 48 tests ±0   48 ✅ ±0  0 💤 ±0  0 ❌ ±0 
201 runs  ±0  201 ✅ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit 1531889. ± Comparison against base commit 370c48c.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 23 0 0 0.19s
✅ DOCKERFILE hadolint 4 0 0 0.19s
✅ JSON npm-package-json-lint yes no no 0.52s
✅ JSON prettier 44 6 0 0 0.79s
✅ JSON v8r 44 0 0 17.38s
✅ MARKDOWN markdownlint 13 0 0 0 1.21s
✅ MARKDOWN markdown-table-formatter 13 0 0 0 0.3s
✅ REPOSITORY betterleaks yes no no 1.13s
✅ REPOSITORY checkov yes no no 29.42s
✅ REPOSITORY gitleaks yes no no 1.15s
✅ REPOSITORY git_diff yes no no 0.01s
✅ REPOSITORY grype yes no no 68.33s
⚠️ REPOSITORY osv-scanner yes 1 no 0.68s
✅ REPOSITORY secretlint yes no no 2.32s
✅ REPOSITORY syft yes no no 3.02s
✅ REPOSITORY trivy yes no no 14.85s
✅ REPOSITORY trivy-sbom yes no no 0.3s
✅ REPOSITORY trufflehog yes no no 6.59s
⚠️ SPELL lychee 115 2 0 34.9s
✅ YAML prettier 35 0 0 0 1.28s
✅ YAML v8r 35 0 0 15.29s
✅ YAML yamllint 35 0 0 1.66s

Detailed Issues

⚠️ SPELL / lychee - 2 errors
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....147
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........2
⛔ Unsupported......2

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Errors in README.md
[502] https://github.com/orgs/philips-software/packages/container/package/amp-devcontainer-rust (at 60:3) | Rejected status code: 502 Bad Gateway | Followed 1 redirect. Redirects: https://github.com/orgs/philips-software/packages/container/package/amp-devcontainer-rust --[302]--> https://github.com/philips-software/amp-devcontainer/pkgs/container/amp-devcontainer-rust

Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 error
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned package-lock.json file and found 73 packages
End status: 104 dirs visited, 339 inodes visited, 8 Extract calls, 44.394082ms elapsed, 44.394282ms wall time

Total 2 packages affected by 2 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 2 Unknown) from 1 ecosystem.
0 vulnerabilities can be fixed.

+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| OSV URL                           | CVSS | ECOSYSTEM | PACKAGE    | VERSION | FIXED VERSION | SOURCE                                            |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110 |      | crates.io | bare-metal | 0.2.5   | --            | test/embedded-rust/workspace/cortex-m/Cargo.lock  |
| https://osv.dev/RUSTSEC-2026-0110 |      | crates.io | bare-metal | 0.2.5   | --            | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

@sonarqubecloud

Copy link
Copy Markdown

Comment thread .github/workflows/update-dependencies.yml Dismissed
Comment thread .github/workflows/update-dependencies.yml Dismissed
Comment thread .github/workflows/wc-build-push.yml Dismissed
Comment thread .github/workflows/wc-build-push.yml Dismissed
Comment thread .github/workflows/wc-build-push.yml Dismissed
@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1375

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 200.14 MB 200.14 MB 730 B (0%) 🔽
linux/arm64 196.35 MB 196.35 MB 735 B (0%) 🔽

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1375

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 406.07 MB 406.07 MB 782 B (0%) 🔽
linux/arm64 357.64 MB 357.64 MB 1.17 kB (0%) 🔽

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1375

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 468.96 MB 468.96 MB 1.03 kB (0%) 🔽
linux/arm64 419.91 MB 419.91 MB 995 B (0%) 🔽

@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1375

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 372.13 MB 372.13 MB 343 B (0%) 🔽
linux/arm64 352.26 MB 352.26 MB 416 B (0%) 🔽

@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 23, 2026 07:15 — with GitHub Actions Inactive
@github-actions

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1375

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 560.5 MB 560.5 MB 356 B (0%) 🔽
linux/arm64 538.95 MB 538.95 MB +1.24 kB (+0%) 🔼

@rjaegers
Ron (rjaegers) enabled auto-merge July 23, 2026 07:34
@rjaegers
Ron (rjaegers) added this pull request to the merge queue Jul 23, 2026
Merged via the queue into main with commit 0f31ce4 Jul 23, 2026
100 of 103 checks passed
@rjaegers
Ron (rjaegers) deleted the chore/pin-to-released-actions branch July 23, 2026 07:56
@github-actions

Copy link
Copy Markdown
Contributor

Pull Request Report (#1375)

Static measures

Description Value
Number of added lines 6
Number of deleted lines 6
Number of changed files 3
Number of commits 3
Number of reviews 3
Number of comments (w/o review comments) 9
Number of reviews that contains a comment to resolve 2
Number of reviews that requested a change from the author 0
Number of reviews that approved the Pull Request 1
Get the total number of participants of a Pull Request 6

Time related measures

Description Value
PR lead time (from creation to close of PR) 23.6 Hours
Time that was spend on the branch before the PR was created 1.4 Min
Time that was spend on the branch before the PR was merged 23.6 Hours
Time to merge after last review 16.5 Hours

Status check related measures

Description Value
Total runtime for last status check run (Workflow for PR) 2.3 Hours
Total time spend in last status check run on PR 16.2 Hours

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants