Skip to content

Add Sources of Component Variables to atmos describe component command. Update docs - #283

Merged
Andriy Knysh (aknysh) merged 40 commits into
masterfrom
update-describe-command
Dec 27, 2022
Merged

Andriy Knysh (aknysh) merged 40 commits into
masterfrom
update-describe-command

Conversation

@aknysh

@aknysh Andriy Knysh (aknysh) commented Dec 24, 2022 •

Copy link
Copy Markdown
Member

what

why

The atmos describe component command outputs the final deep-merged component configuration in YAML format.

The output contains the following sections:

  • atmos_component - Atmos component name
  • atmos_stack - Atmos stack name
  • backend - Terraform backend configuration
  • backend_type - Terraform backend type
  • command - the binary to execute when provisioning the component (e.g. terraform, terraform-1, helmfile)
  • component - the Terraform component for which the Atmos component provides configuration
  • deps - a list of stack dependencies (stack config files where the component settings are defined, either inline or via imports)
  • env - a list of ENV variables defined for the Atmos component
  • inheritance - component's inheritance chain
  • metadata - component's metadata config
  • remote_state_backend - Terraform backend config for remote state
  • remote_state_backend_type - Terraform backend type for remote state
  • settings - component settings (free-form map)
  • sources - sources of the component's variables
  • vars - the final deep-merged component variables that are provided to Terraform and Helmfile when executing atmos terraform and atmos helmfile commands
  • workspace - Terraform workspace for the Atmos component

The sources.vars section of the output shows the final deep-merged component's variables and their inheritance chain.

Each variable descriptor has the following schema:

  • final_value - the final value of the variable after Atmos processes and deep-merges all values from all stack config files

  • name - the variable name

  • stack_dependencies - the variable's inheritance chain (stack config files where the values for the variable were provided). It has the following schema:

    • stack_file - the stack config file where a value for the variable was provided
    • stack_file_section - the section of the stack config file where the value for the variable was provided
    • variable_value - the variable's value
    • dependency_type - how the variable was defined (inline or import). inline means the variable was defined in one of the sections in the stack config file. import means the stack config file where the variable is defined was imported into the parent Atmos stack

For example:

atmos describe component test/test-component-override-3 -s tenant1-ue2-dev
sources:
  vars:
    enabled:
      final_value: true
      name: enabled
      stack_dependencies:
        - dependency_type: import
          stack_file: catalog/terraform/test-component
          stack_file_section: components.terraform.vars
          variable_value: true
        - dependency_type: inline
          stack_file: orgs/cp/tenant1/dev/us-east-2
          stack_file_section: terraform.vars
          variable_value: false
        - dependency_type: inline
          stack_file: orgs/cp/tenant1/dev/us-east-2
          stack_file_section: vars
          variable_value: true
    environment:
      final_value: ue2
      name: environment
      stack_dependencies:
        - dependency_type: import
          stack_file: mixins/region/us-east-2
          stack_file_section: vars
          variable_value: ue2
    namespace:
      final_value: cp
      name: namespace
      stack_dependencies:
        - dependency_type: import
          stack_file: orgs/cp/_defaults
          stack_file_section: vars
          variable_value: cp
    region:
      final_value: us-east-2
      name: region
      stack_dependencies:
        - dependency_type: import
          stack_file: mixins/region/us-east-2
          stack_file_section: vars
          variable_value: us-east-2
    service_1_map:
      final_value:
        a: 1
        b: 6
        c: 7
        d: 8
      name: service_1_map
      stack_dependencies:
        - dependency_type: import
          stack_file: catalog/terraform/services/service-1-override-2
          stack_file_section: components.terraform.vars
          variable_value:
            b: 6
            c: 7
            d: 8
        - dependency_type: import
          stack_file: catalog/terraform/services/service-1-override
          stack_file_section: components.terraform.vars
          variable_value:
            a: 1
            b: 2
            c: 3
    service_1_name:
      final_value: mixin-2
      name: service_1_name
      stack_dependencies:
        - dependency_type: import
          stack_file: catalog/terraform/mixins/test-2
          stack_file_section: components.terraform.vars
          variable_value: mixin-2
        - dependency_type: import
          stack_file: catalog/terraform/mixins/test-1
          stack_file_section: components.terraform.vars
          variable_value: mixin-1
        - dependency_type: import
          stack_file: catalog/terraform/services/service-1-override-2
          stack_file_section: components.terraform.vars
          variable_value: service-1-override-2
        - dependency_type: import
          stack_file: catalog/terraform/tenant1-ue2-dev
          stack_file_section: components.terraform.vars
          variable_value: service-1-override-2
        - dependency_type: import
          stack_file: catalog/terraform/services/service-1-override
          stack_file_section: components.terraform.vars
          variable_value: service-1-override
        - dependency_type: import
          stack_file: catalog/terraform/services/service-1
          stack_file_section: components.terraform.vars
          variable_value: service-1
    stage:
      final_value: dev
      name: stage
      stack_dependencies:
        - dependency_type: import
          stack_file: mixins/stage/dev
          stack_file_section: vars
          variable_value: dev

NOTE: The stack_dependencies inheritance chain shows the variable sources in the reverse order the sources were processed. The first item in the list was processed the last and its variable_value overrode all the previous values of the variable.


For example, the component's enabled variable has the following inheritance chain:

sources:
  vars:
    enabled:
      final_value: true
      name: enabled
      stack_dependencies:
        - dependency_type: import
          stack_file: catalog/terraform/test-component
          stack_file_section: components.terraform.vars
          variable_value: true
        - dependency_type: inline
          stack_file: orgs/cp/tenant1/dev/us-east-2
          stack_file_section: terraform.vars
          variable_value: false
        - dependency_type: inline
          stack_file: orgs/cp/tenant1/dev/us-east-2
          stack_file_section: vars
          variable_value: true

Which we can interpret as follows (reading from the last to the first item in the stack_dependencies list):

  • In the orgs/cp/tenant1/dev/us-east-2 stack config file (the last item in the list), the value for enabled was set to true in the global vars section (inline)

  • Then in the same orgs/cp/tenant1/dev/us-east-2 stack config file, the value for enabled was set to false in the terraform.vars section (inline). This value overrode the value set in the global vars section

  • Finally, in the catalog/terraform/test-component stack config file (which was imported into the parent Atmos stack
    via import), the value for enabled was set to true in the components.terraform.vars section of
    the test/test-component-override-3 Atmos component. This value overrode all the previous values arriving at the final_value: true for the variable. This final value is then set for the enabled variable of the Terraform component test/test-component when Atmos executes atmos terraform apply test/test-component-override-3 -s <stack> command

@aknysh
Andriy Knysh (aknysh) temporarily deployed to preview December 24, 2022 14:37 — with GitHub Actions Inactive
@aknysh
Andriy Knysh (aknysh) temporarily deployed to preview December 24, 2022 14:44 — with GitHub Actions Inactive
@aknysh
Andriy Knysh (aknysh) merged commit aeb9459 into master Dec 27, 2022
@aknysh
Andriy Knysh (aknysh) deleted the update-describe-command branch December 27, 2022 17:03
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request Sep 2, 2026
Bump the pnpm.overrides pin for fast-uri to >=3.1.6, resolving:

- GHSA (#288) host confusion via skipped IDN canonicalization on
  scheme-relative references
- GHSA (#287) SSRF via malformed IPv6 normalization
- GHSA (#286) SSRF via repeated hostname percent-decoding
- GHSA (#285) host confusion via percent-encoded scheme normalization

qs (#283, #284, patched in 6.16.0) is not fixed here: that release is
4 days old and blocked by this repo's 14-day pnpm minimum-release-age
cooldown until ~2026-09-12. browserslist/postcss-selector-parser
(#280-282) were already fixed in b59c389, prior to this branch's
last few merges from main.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request Sep 2, 2026
- golang.org/x/crypto v0.55.0 -> v0.56.0 (go get + go mod tidy), fixing two
  govulncheck alerts (GO-2026-6354, GO-2026-6355): a malicious SSH peer could
  deadlock a connection via crafted channel messages
  (golang.org/x/crypto/ssh). No direct callers in this repo beyond
  pkg/store/providers/github_actions_client.go; verified via go build and
  pkg/store/... tests.
- website pnpm override: fast-uri@^3 -> ^3.1.6 (patched; published 10 days
  ago, clears this repo's 7-day minimum-release-age cooldown).
- regenerate NOTICE to reflect the x/crypto bump.

qs (Dependabot #283/#284, patched at 6.16.0) is intentionally NOT bumped:
6.16.0 was published 4 days ago, still inside website/.npmrc's 7-day
minimum-release-age cooldown -- forcing it in via
minimumReleaseAgeExclude would defeat the cooldown's purpose. Will pick it
up once it clears.

browserslist (#281/#282) and postcss-selector-parser (#280) are already
fixed on this branch from an earlier commit; GitHub just hasn't re-scanned
yet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request Sep 4, 2026
…-4mjr-xmp4-gh2g

Dependabot alerts #283/#284: the website/pnpm.overrides pin for the
transitive qs dependency (via docusaurus -> webpack-dev-server ->
express) was capped at ^6.15.2, keeping it on the vulnerable 6.15.3.
Both advisories are fixed in 6.16.0, a minor bump allowed by
dependabot.yml's major-version ignore policy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
zack-is-cool pushed a commit to zack-is-cool/atmos that referenced this pull request Sep 8, 2026
…dposse#2878)

* docs(prd): correct stale status headers found during Terragrunt migration research

Checkpoint before syncing this branch with origin/main — these fixes were made
against an older snapshot and will likely need rework once current upstream
content is merged in.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(migration): add Terragrunt migration skill reference and correct stale PRD statuses

Adds the atmos-migration skill's Terragrunt reference (classic and Stacks
patterns, concept mapping, migration workflow), hands-on-validated against a
real Terragrunt Stacks example run end to end on the floci/aws emulator.
Corrects four PRD status headers that had gone stale relative to shipped
code, fixes pre-existing EditorConfig indentation violations the commit hook
surfaced in two of those files, and documents the mocks/--use-mocks feature
in the website Terragrunt migration guide as the direct equivalent of
mock_outputs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(docs): use clean !terraform.state syntax and fix EditorConfig indentation

CI caught two real issues in the new Terragrunt migration reference:
- Two examples used the legacy doubled-double-quote YQ escaping
  (!terraform.state x ".field // ""default""") instead of the clean current
  syntax (!terraform.state x .field // "default"), which scripts/check-
  terraform-example-syntax.sh flags outside its designated compatibility
  fixtures.
- The "Migration Workflow" numbered list used 3-space continuation
  indentation, not a multiple of the repo's 2-space EditorConfig setting.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(docs): address CodeRabbit findings and field-test gaps on Terragrunt migration guide

Reconciles PRD status claims that contradicted themselves (dag-concurrent-execution.md
Phase 3 is only partially shipped, not fully; custom-hooks.md's relative "today" date),
completes the from-terragrunt.md 5-level merge listing, and fixes a hallucinated
`settings.terraform.provider_overrides` key found via hands-on field testing. Also
recommends `atmos list affected` over `atmos describe affected` for human-run migration
comparisons (table output vs. a wall of YAML), notes both diff committed trees only,
and updates the Change Tracking table to the current `dependencies.files`/`folders`
syntax instead of the legacy inline `kind: file`/`kind: folder` form.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(docs): resolve second CodeRabbit review round on Terragrunt migration guide

Step 3 of the migration workflow still mapped mock_outputs to the YQ // "default"
pattern, contradicting the mocks:/--use-mocks mapping documented a few paragraphs
earlier. Quotes the YQ default expressions for consistency with
atmos-yaml-functions/SKILL.md and atmos-components/SKILL.md.

dag-concurrent-execution.md had two more self-contradictions: the Subprocess
Execution section still described the os.Stdout race that Phase 1 already fixed
(terraform_plan_diff.go now captures via bytes.Buffer), and the Resolved Questions
section claimed cross-type dependency syntax was "solved by PR cloudposse#2193" — traced the
code and found pkg/scheduler/adapters/terraform.go explicitly skips any dependency
whose kind isn't "terraform", so the kind field is schema-parseable but not yet
consumed by the scheduler; corrected to match the already-accurate Phase 3 status.

terragrunt.mdx's list-affected example claimed to compare against main by default
without passing --ref; list affected has no --base flag (unlike describe affected),
so made the comparison explicit with --ref main instead.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore: trigger CI re-run

* fix(mocks): correct provenance rendering, error wording, and // default parity

A field test of --use-mocks found `describe component` silently rendering
empty output whenever a component's provenance path wasn't matched due to an
unnormalized lookup, a mock-output error that mislabeled the output name as a
component name, and a YQ `//` default that only rescued a missing key inside
a declared `mocks` map, not a component with no `mocks` section at all --
inconsistent with how `//` already rescues real state. Also cross-references
the mocks:/--use-mocks feature from the docs pages and skill most likely to
be read first.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(snapshots): regenerate describe_component golden snapshots after provenance fix

The filterEmptySections fix (6c22503) corrected describe_component to stop
silently dropping real sections (backend, metadata, env, overrides) that lack
a stack-root section of the same name. CI caught the resulting golden
snapshot drift on both linux and macos; regenerated via
`-regenerate-snapshots` per CLAUDE.md, verified the diffs only add the
previously-hidden, now-correct content.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(provenance): address CodeRabbit review on PR cloudposse#2878

Add periods to the rendering-constant comments (godot's inline-comment
scope missed these, but CLAUDE.md's comment convention still applies), and
cover the array-element provenance path (vars[0].foo) alongside the
already-tested dot-nested form. The trailing-period finding on
ErrTerraformMockOutputNotDeclared was already resolved by an earlier commit
in this PR — no change needed there.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(test): widen RunSession timeouts to fix Windows CI flake

Acceptance Tests (windows, shard 4/10) failed with ErrWaitTimeout in
TestRunSessionExecutesScriptedShellActions and
TestRunSessionAppliesDirectoryAndEnvironment: the write->echo->match round
trip against a spawned child (no PTY on Windows, unlike session_unix.go)
never completed within the 2s wait/3s context budget. Widened both to 8s/15s
across all four RunSession-based tests; no production code changed since
static review found no concrete pipe-wiring bug. Not reproduced locally (no
Windows environment available) — documented in docs/fixes/ per this repo's
convention for unconfirmed Windows-only CI fixes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(fixes): address CodeRabbit findings on PR cloudposse#2878

- Add a text language tag to the failure-output fenced block (markdownlint
  MD040).
- Correct the documented timeout values to match what actually shipped after
  merge-conflict resolution: 10s per wait (not 8s), and 25s outer context for
  TestRunSessionAppliesDirectoryAndEnvironment's two sequential waits (not
  15s) — the outer context must exceed the sum of sequential wait timeouts,
  not just one of them, per waitForOutput's ctx.Done()-vs-deadline-timer race.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(fixes): document CI exit-code test failure as a registry network flake

Acceptance Tests (linux, shard 9/10) failed
TestCLICommands/atmos_exit_code_should_be_same_as_command_exit_code_(2) with
"Expected exit code 2, got 1". The real cause was tofu init timing out
reaching registry.opentofu.org (context deadline exceeded) before any plan
could run -- confirmed the fixture has no registry-mirror config to regress,
and the sibling (0)/(1) exit-code cases in the same file passed. No code
change: there's nothing in this repo that fixes a transient outage on a
public third-party registry, and loosening the exit-code assertion would
mask a real CLI exit-code-propagation regression if one ever occurs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(ci): don't fail test-required/k3s-required on a cancelled run

All five attached failure logs (Acceptance Tests linux/macos/windows,
[k3s] demo-helmfile, Build windows) traced to one event: workflow run
33394180592 on this PR was cancelled (confirmed via gh api), not failed. The
test/k3s matrix jobs were skipped as a result, but the -required gate jobs
(if: always()) still ran and misreported the cancellation as a hard failure
("expected 10 shard jobs, found 0" / "k3s matrix result was 'skipped'").

needs.test.result and needs.k3s.result both report "skipped" for a genuine
upstream failure and for a whole-run cancellation alike, so they can't
distinguish the two - cancelled() can, and is the fix. It's only valid in an
if:, not inside a run: script (caught by actionlint), so both gates get a
"Skip verification" step under if: cancelled() plus if: !cancelled() on
their existing check steps, leaving the fail-loudly-on-genuine-anomalies
logic untouched for real failures.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* [autocommit] formatting fixes

* fix(ci): pin cuelang.org/go's NOTICE URL to a deterministic override

Review Dependency Licenses failed: NOTICE had "URL: Unknown" for
cuelang.org/go, but a fresh generate-notice.sh run resolved a real URL,
tripping the out-of-date check. Root cause was a race, not one bad run:
this branch's merge commit already had the correct URL, but a subsequent
[autocommit] formatting fixes commit (atmos-pro[bot]) regenerated NOTICE
under a network condition where go-licenses' live resolution for
cuelang.org/go failed, silently reverting it to "Unknown" and committing
that regression - exactly the oscillation scripts/generate-notice.sh's
REPO_OVERRIDES mechanism exists to prevent for modules go-licenses can't
resolve reliably, cuelang.org/go just wasn't in the list yet.

Added it (repo github.com/cue-lang/cue, no tag prefix, LICENSE path),
which reconstructs the exact URL CI itself resolved
(https://github.com/cue-lang/cue/blob/v0.16.1/LICENSE) from go.mod's
pinned v0.16.1 with no network dependency, and applied that one-line NOTICE
fix by hand: a local generate-notice.sh run silently produced a truncated
102-dependency report (vs. CI's 643) with 0 Apache-2.0/BSD licenses found,
consistent with this machine lacking a Linux-targeting C cross-compiler for
CGO_ENABLED=1 GOOS=linux GOARCH=amd64 - so that broken local output was
discarded rather than committed, and the NOTICE line was hand-verified
against the override's own URL-construction formula and go.mod's version
instead.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(ci): retry go install go-licenses on transient sum.golang.org failures

Review Dependency Licenses failed installing go-licenses@v1.6.0: a
mid-stream HTTP/2 reset (stream ID 1155; INTERNAL_ERROR) reading
sum.golang.org during go install's go.sum verification, unrelated to any
actual dependency problem and unrelated to the immediately preceding commit
on this branch (confirmed via gh api against head_sha 5ac5d97, which only
touched an unrelated NOTICE URL override).

Same failure class already fixed once for go mod download
(docs/fixes/2026-08-25-build-atmos-go-mod-download-retry.md, later ported to
magefiles/build.go's runGoModDownload) - just hit a different network call
(go install's dependency-graph resolution) in a different script. Wrapped
generate-notice.sh's bare go install in the same 3-attempt/15s-backoff until
loop, matching .github/actions/download-artifact-retry's convention.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(docs): replace a literal tab with spaces in a fix-log fenced block

Run pre-commit hooks failed atmos-validate-editorconfig: a fenced code block
in docs/fixes/2026-08-31-notice-go-licenses-install-retry.md quoted a Go
toolchain error message verbatim, including its original tab-indented
continuation line - violating this repo's *.md indent_style=space rule.
Replaced the literal tab with two spaces (matching indent_size=2), content
otherwise unchanged. Scanned every other 2026-08-31 fix-log doc added this
session for the same issue; none found.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(blog): bump terraform-component-mocks date to when its content changed

fix(mocks) commit 6c22503 edited this post's body (the // default
behavior clarification) on 2026-08-06, but the post kept displaying/sorting
under its original 2026-07-15 publish date since Docusaurus has no separate
date. Added an explicit date: frontmatter override for the edit date,
matching this repo's existing convention for date overrides (e.g.
2026-01-02-unified-task-runner.mdx).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(security): remediate 4 Dependabot alerts

- google.golang.org/grpc v1.82.1 -> v1.83.1 (go get + go mod tidy),
  bumping compatible transitive deps
- website pnpm overrides: browserslist -> ^4.28.7, postcss-selector-parser
  (^6.0.11 and ^6.0.16 requesters) -> ^6.1.3
- regenerate NOTICE to reflect the grpc bump

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(fixes): document atmos_vendor_pull DNS-resolution CI flake

Acceptance Tests (macos, shard 4/10) failed with "tty did not match
pattern \"Vendored 3 components\"" because git itself could not resolve
github.com on the runner (OS-level resolver failure, corroborated by the
same job's Harden Runner network log) -- not a code regression. No code
change; re-running the job is expected to pass.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: address CodeRabbit review findings on mocks docs, fix-logs, and noticegen tests

- agent-skills/skills/atmos-migration/references/from-terragrunt.md: correct
  the mock_outputs -> mocks migration guidance -- Terragrunt scopes
  mock_outputs per dependency consumer, Atmos scopes mocks per producer
  component (shared by every consumer). Document that a shared mock value
  only works when every consumer agrees on it, and that a genuinely
  different per-consumer value needs its own producer component instance.
- docs/fixes/2026-08-31-notice-go-licenses-install-retry.md: the retry loop
  now lives in tools/noticegen/report.go's ensureGoLicenses (tested in
  tools/noticegen/report_test.go), not scripts/generate-notice.sh, which was
  deleted when the NOTICE generator was rewritten as a Go tool. Updated the
  title, Context, Changes, and Validation sections accordingly.
- docs/fixes/2026-08-31-required-check-gates-fail-on-cancelled-run.md:
  reworded "passing (all-steps-skipped) job" to "a passing job whose
  verification steps are skipped" -- the explicit Skip verification step
  still runs, so the job isn't literally all-skipped.
- tools/noticegen/report.go: extracted lookPathGoLicenses as a package-level
  var (previously a direct exec.LookPath call inside ensureGoLicenses) so
  tests can force the "not found" branch deterministically.
- tools/noticegen/report_test.go: both retry tests now inject
  lookPathGoLicenses to return exec.ErrNotFound, instead of relying on the
  real PATH not already containing go-licenses -- which it may, e.g. from a
  prior local run, silently skipping runGoInstall and making the retry
  assertions vacuous.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: address CodeRabbit findings on SKILL.md link casing and vendor-pull fix-log wording

- agent-skills/skills/atmos-migration/SKILL.md: lowercase the
  from-terragrunt.md reference link's display text to match the actual
  lowercase repo path and the style of the overview section's own link.
- docs/fixes/2026-09-02-vendor-pull-dns-resolution-flake.md: correct the
  fixture description -- tests/fixtures/scenarios/vendor/vendor.yaml
  exercises a local file:// source and a git::https:// source, not an OCI
  source or a separate plain-HTTPS source.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(security): remediate 3 Dependabot/CodeQL alerts

- golang.org/x/crypto v0.55.0 -> v0.56.0 (go get + go mod tidy), fixing two
  govulncheck alerts (GO-2026-6354, GO-2026-6355): a malicious SSH peer could
  deadlock a connection via crafted channel messages
  (golang.org/x/crypto/ssh). No direct callers in this repo beyond
  pkg/store/providers/github_actions_client.go; verified via go build and
  pkg/store/... tests.
- website pnpm override: fast-uri@^3 -> ^3.1.6 (patched; published 10 days
  ago, clears this repo's 7-day minimum-release-age cooldown).
- regenerate NOTICE to reflect the x/crypto bump.

qs (Dependabot cloudposse#283/cloudposse#284, patched at 6.16.0) is intentionally NOT bumped:
6.16.0 was published 4 days ago, still inside website/.npmrc's 7-day
minimum-release-age cooldown -- forcing it in via
minimumReleaseAgeExclude would defeat the cooldown's purpose. Will pick it
up once it clears.

browserslist (cloudposse#281/cloudposse#282) and postcss-selector-parser (cloudposse#280) are already
fixed on this branch from an earlier commit; GitHub just hasn't re-scanned
yet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(ci): whitelist go.googlesource.com/go.dev/pkg.go.dev for CodeQL Go jobs

StepSecurity's blocked-call detections (analyzed via the stepsecurity MCP
server) showed the analyze and govulncheck jobs' harden-runner egress
policies blocking go.googlesource.com, go.dev, and pkg.go.dev during Go
module/toolchain resolution -- both are trusted Go project domains
(GOTOOLCHAIN auto-download and go-getter's git-host fallback path).
go.googlesource.com was already allowed for govulncheck but missing from
analyze; go.dev and pkg.go.dev were missing from both. Also removed a
duplicate storage.googleapis.com entry in analyze's list.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Co-authored-by: atmos-pro[bot] <173522224+atmos-pro[bot]@users.noreply.github.com>
Co-authored-by: Andriy Knysh <aknysh@users.noreply.github.com>
zack-is-cool pushed a commit to zack-is-cool/atmos that referenced this pull request Sep 8, 2026
…udposse#3010)

* fix(store): don't fail the whole registry build on one bad store

NewStoreRegistry aborted the entire stores: config load if a single
store failed to resolve or construct, even one nothing referenced --
one misconfigured store took down every store, every remote-state
lookup, and (transitively) every subcommand's config load. The kind
not found error also omitted the store name, making a multi-store
config hard to triage from the log alone.

A store that fails to resolve (unknown kind), fails a secret/kind
validation, or fails to construct is now skipped and logged as a
named warning instead of returned as a fatal error. Code that
actually looks up a skipped store by name still gets a clear error
at the point of use.

Closes cloudposse#2930

* fix(store): correct grammar in NewStoreRegistry doc comment

Addresses CodeRabbit review feedback on PR cloudposse#3010.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(security): bump qs to 6.16.0, fixing GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g

Dependabot alerts cloudposse#283/cloudposse#284: the website/pnpm.overrides pin for the
transitive qs dependency (via docusaurus -> webpack-dev-server ->
express) was capped at ^6.15.2, keeping it on the vulnerable 6.15.3.
Both advisories are fixed in 6.16.0, a minor bump allowed by
dependabot.yml's major-version ignore policy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>

This branch was previously deployed

1 inactive deployment
preview — 8fa6ce72 Deployed Dec 24, 2022 by aknysh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants