Repository navigation
Bump github.com/open-policy-agent/opa from 0.47.3 to 0.47.4 - #284
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa) from 0.47.3 to 0.47.4. - [Release notes](https://github.com/open-policy-agent/opa/releases) - [Changelog](https://github.com/open-policy-agent/opa/blob/main/CHANGELOG.md) - [Commits](open-policy-agent/opa@v0.47.3...v0.47.4) --- updated-dependencies: - dependency-name: github.com/open-policy-agent/opa dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
requested review from
Matt Gowie (Gowiem) and
Yonatan Koren (korenyoni)
December 25, 2022 00:10
Contributor
Author
|
The following labels could not be found: |
Contributor
Author
|
Looks like github.com/open-policy-agent/opa is up-to-date now, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/go_modules/github.com/open-policy-agent/opa-0.47.4
branch
December 27, 2022 17:03
Erik Osterman (Cloud Posse) (osterman)
added a commit
that referenced
this pull request
Sep 2, 2026
Bump the pnpm.overrides pin for fast-uri to >=3.1.6, resolving: - GHSA (#288) host confusion via skipped IDN canonicalization on scheme-relative references - GHSA (#287) SSRF via malformed IPv6 normalization - GHSA (#286) SSRF via repeated hostname percent-decoding - GHSA (#285) host confusion via percent-encoded scheme normalization qs (#283, #284, patched in 6.16.0) is not fixed here: that release is 4 days old and blocked by this repo's 14-day pnpm minimum-release-age cooldown until ~2026-09-12. browserslist/postcss-selector-parser (#280-282) were already fixed in b59c389, prior to this branch's last few merges from main. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Erik Osterman (Cloud Posse) (osterman)
added a commit
that referenced
this pull request
Sep 2, 2026
- golang.org/x/crypto v0.55.0 -> v0.56.0 (go get + go mod tidy), fixing two govulncheck alerts (GO-2026-6354, GO-2026-6355): a malicious SSH peer could deadlock a connection via crafted channel messages (golang.org/x/crypto/ssh). No direct callers in this repo beyond pkg/store/providers/github_actions_client.go; verified via go build and pkg/store/... tests. - website pnpm override: fast-uri@^3 -> ^3.1.6 (patched; published 10 days ago, clears this repo's 7-day minimum-release-age cooldown). - regenerate NOTICE to reflect the x/crypto bump. qs (Dependabot #283/#284, patched at 6.16.0) is intentionally NOT bumped: 6.16.0 was published 4 days ago, still inside website/.npmrc's 7-day minimum-release-age cooldown -- forcing it in via minimumReleaseAgeExclude would defeat the cooldown's purpose. Will pick it up once it clears. browserslist (#281/#282) and postcss-selector-parser (#280) are already fixed on this branch from an earlier commit; GitHub just hasn't re-scanned yet. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Erik Osterman (Cloud Posse) (osterman)
added a commit
that referenced
this pull request
Sep 4, 2026
…-4mjr-xmp4-gh2g Dependabot alerts #283/#284: the website/pnpm.overrides pin for the transitive qs dependency (via docusaurus -> webpack-dev-server -> express) was capped at ^6.15.2, keeping it on the vulnerable 6.15.3. Both advisories are fixed in 6.16.0, a minor bump allowed by dependabot.yml's major-version ignore policy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
zack-is-cool
pushed a commit
to zack-is-cool/atmos
that referenced
this pull request
Sep 8, 2026
…dposse#2878) * docs(prd): correct stale status headers found during Terragrunt migration research Checkpoint before syncing this branch with origin/main — these fixes were made against an older snapshot and will likely need rework once current upstream content is merged in. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(migration): add Terragrunt migration skill reference and correct stale PRD statuses Adds the atmos-migration skill's Terragrunt reference (classic and Stacks patterns, concept mapping, migration workflow), hands-on-validated against a real Terragrunt Stacks example run end to end on the floci/aws emulator. Corrects four PRD status headers that had gone stale relative to shipped code, fixes pre-existing EditorConfig indentation violations the commit hook surfaced in two of those files, and documents the mocks/--use-mocks feature in the website Terragrunt migration guide as the direct equivalent of mock_outputs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(docs): use clean !terraform.state syntax and fix EditorConfig indentation CI caught two real issues in the new Terragrunt migration reference: - Two examples used the legacy doubled-double-quote YQ escaping (!terraform.state x ".field // ""default""") instead of the clean current syntax (!terraform.state x .field // "default"), which scripts/check- terraform-example-syntax.sh flags outside its designated compatibility fixtures. - The "Migration Workflow" numbered list used 3-space continuation indentation, not a multiple of the repo's 2-space EditorConfig setting. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(docs): address CodeRabbit findings and field-test gaps on Terragrunt migration guide Reconciles PRD status claims that contradicted themselves (dag-concurrent-execution.md Phase 3 is only partially shipped, not fully; custom-hooks.md's relative "today" date), completes the from-terragrunt.md 5-level merge listing, and fixes a hallucinated `settings.terraform.provider_overrides` key found via hands-on field testing. Also recommends `atmos list affected` over `atmos describe affected` for human-run migration comparisons (table output vs. a wall of YAML), notes both diff committed trees only, and updates the Change Tracking table to the current `dependencies.files`/`folders` syntax instead of the legacy inline `kind: file`/`kind: folder` form. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(docs): resolve second CodeRabbit review round on Terragrunt migration guide Step 3 of the migration workflow still mapped mock_outputs to the YQ // "default" pattern, contradicting the mocks:/--use-mocks mapping documented a few paragraphs earlier. Quotes the YQ default expressions for consistency with atmos-yaml-functions/SKILL.md and atmos-components/SKILL.md. dag-concurrent-execution.md had two more self-contradictions: the Subprocess Execution section still described the os.Stdout race that Phase 1 already fixed (terraform_plan_diff.go now captures via bytes.Buffer), and the Resolved Questions section claimed cross-type dependency syntax was "solved by PR cloudposse#2193" — traced the code and found pkg/scheduler/adapters/terraform.go explicitly skips any dependency whose kind isn't "terraform", so the kind field is schema-parseable but not yet consumed by the scheduler; corrected to match the already-accurate Phase 3 status. terragrunt.mdx's list-affected example claimed to compare against main by default without passing --ref; list affected has no --base flag (unlike describe affected), so made the comparison explicit with --ref main instead. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore: trigger CI re-run * fix(mocks): correct provenance rendering, error wording, and // default parity A field test of --use-mocks found `describe component` silently rendering empty output whenever a component's provenance path wasn't matched due to an unnormalized lookup, a mock-output error that mislabeled the output name as a component name, and a YQ `//` default that only rescued a missing key inside a declared `mocks` map, not a component with no `mocks` section at all -- inconsistent with how `//` already rescues real state. Also cross-references the mocks:/--use-mocks feature from the docs pages and skill most likely to be read first. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * test(snapshots): regenerate describe_component golden snapshots after provenance fix The filterEmptySections fix (6c22503) corrected describe_component to stop silently dropping real sections (backend, metadata, env, overrides) that lack a stack-root section of the same name. CI caught the resulting golden snapshot drift on both linux and macos; regenerated via `-regenerate-snapshots` per CLAUDE.md, verified the diffs only add the previously-hidden, now-correct content. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(provenance): address CodeRabbit review on PR cloudposse#2878 Add periods to the rendering-constant comments (godot's inline-comment scope missed these, but CLAUDE.md's comment convention still applies), and cover the array-element provenance path (vars[0].foo) alongside the already-tested dot-nested form. The trailing-period finding on ErrTerraformMockOutputNotDeclared was already resolved by an earlier commit in this PR — no change needed there. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(test): widen RunSession timeouts to fix Windows CI flake Acceptance Tests (windows, shard 4/10) failed with ErrWaitTimeout in TestRunSessionExecutesScriptedShellActions and TestRunSessionAppliesDirectoryAndEnvironment: the write->echo->match round trip against a spawned child (no PTY on Windows, unlike session_unix.go) never completed within the 2s wait/3s context budget. Widened both to 8s/15s across all four RunSession-based tests; no production code changed since static review found no concrete pipe-wiring bug. Not reproduced locally (no Windows environment available) — documented in docs/fixes/ per this repo's convention for unconfirmed Windows-only CI fixes. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(fixes): address CodeRabbit findings on PR cloudposse#2878 - Add a text language tag to the failure-output fenced block (markdownlint MD040). - Correct the documented timeout values to match what actually shipped after merge-conflict resolution: 10s per wait (not 8s), and 25s outer context for TestRunSessionAppliesDirectoryAndEnvironment's two sequential waits (not 15s) — the outer context must exceed the sum of sequential wait timeouts, not just one of them, per waitForOutput's ctx.Done()-vs-deadline-timer race. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(fixes): document CI exit-code test failure as a registry network flake Acceptance Tests (linux, shard 9/10) failed TestCLICommands/atmos_exit_code_should_be_same_as_command_exit_code_(2) with "Expected exit code 2, got 1". The real cause was tofu init timing out reaching registry.opentofu.org (context deadline exceeded) before any plan could run -- confirmed the fixture has no registry-mirror config to regress, and the sibling (0)/(1) exit-code cases in the same file passed. No code change: there's nothing in this repo that fixes a transient outage on a public third-party registry, and loosening the exit-code assertion would mask a real CLI exit-code-propagation regression if one ever occurs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(ci): don't fail test-required/k3s-required on a cancelled run All five attached failure logs (Acceptance Tests linux/macos/windows, [k3s] demo-helmfile, Build windows) traced to one event: workflow run 33394180592 on this PR was cancelled (confirmed via gh api), not failed. The test/k3s matrix jobs were skipped as a result, but the -required gate jobs (if: always()) still ran and misreported the cancellation as a hard failure ("expected 10 shard jobs, found 0" / "k3s matrix result was 'skipped'"). needs.test.result and needs.k3s.result both report "skipped" for a genuine upstream failure and for a whole-run cancellation alike, so they can't distinguish the two - cancelled() can, and is the fix. It's only valid in an if:, not inside a run: script (caught by actionlint), so both gates get a "Skip verification" step under if: cancelled() plus if: !cancelled() on their existing check steps, leaving the fail-loudly-on-genuine-anomalies logic untouched for real failures. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * [autocommit] formatting fixes * fix(ci): pin cuelang.org/go's NOTICE URL to a deterministic override Review Dependency Licenses failed: NOTICE had "URL: Unknown" for cuelang.org/go, but a fresh generate-notice.sh run resolved a real URL, tripping the out-of-date check. Root cause was a race, not one bad run: this branch's merge commit already had the correct URL, but a subsequent [autocommit] formatting fixes commit (atmos-pro[bot]) regenerated NOTICE under a network condition where go-licenses' live resolution for cuelang.org/go failed, silently reverting it to "Unknown" and committing that regression - exactly the oscillation scripts/generate-notice.sh's REPO_OVERRIDES mechanism exists to prevent for modules go-licenses can't resolve reliably, cuelang.org/go just wasn't in the list yet. Added it (repo github.com/cue-lang/cue, no tag prefix, LICENSE path), which reconstructs the exact URL CI itself resolved (https://github.com/cue-lang/cue/blob/v0.16.1/LICENSE) from go.mod's pinned v0.16.1 with no network dependency, and applied that one-line NOTICE fix by hand: a local generate-notice.sh run silently produced a truncated 102-dependency report (vs. CI's 643) with 0 Apache-2.0/BSD licenses found, consistent with this machine lacking a Linux-targeting C cross-compiler for CGO_ENABLED=1 GOOS=linux GOARCH=amd64 - so that broken local output was discarded rather than committed, and the NOTICE line was hand-verified against the override's own URL-construction formula and go.mod's version instead. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(ci): retry go install go-licenses on transient sum.golang.org failures Review Dependency Licenses failed installing go-licenses@v1.6.0: a mid-stream HTTP/2 reset (stream ID 1155; INTERNAL_ERROR) reading sum.golang.org during go install's go.sum verification, unrelated to any actual dependency problem and unrelated to the immediately preceding commit on this branch (confirmed via gh api against head_sha 5ac5d97, which only touched an unrelated NOTICE URL override). Same failure class already fixed once for go mod download (docs/fixes/2026-08-25-build-atmos-go-mod-download-retry.md, later ported to magefiles/build.go's runGoModDownload) - just hit a different network call (go install's dependency-graph resolution) in a different script. Wrapped generate-notice.sh's bare go install in the same 3-attempt/15s-backoff until loop, matching .github/actions/download-artifact-retry's convention. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(docs): replace a literal tab with spaces in a fix-log fenced block Run pre-commit hooks failed atmos-validate-editorconfig: a fenced code block in docs/fixes/2026-08-31-notice-go-licenses-install-retry.md quoted a Go toolchain error message verbatim, including its original tab-indented continuation line - violating this repo's *.md indent_style=space rule. Replaced the literal tab with two spaces (matching indent_size=2), content otherwise unchanged. Scanned every other 2026-08-31 fix-log doc added this session for the same issue; none found. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(blog): bump terraform-component-mocks date to when its content changed fix(mocks) commit 6c22503 edited this post's body (the // default behavior clarification) on 2026-08-06, but the post kept displaying/sorting under its original 2026-07-15 publish date since Docusaurus has no separate date. Added an explicit date: frontmatter override for the edit date, matching this repo's existing convention for date overrides (e.g. 2026-01-02-unified-task-runner.mdx). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(security): remediate 4 Dependabot alerts - google.golang.org/grpc v1.82.1 -> v1.83.1 (go get + go mod tidy), bumping compatible transitive deps - website pnpm overrides: browserslist -> ^4.28.7, postcss-selector-parser (^6.0.11 and ^6.0.16 requesters) -> ^6.1.3 - regenerate NOTICE to reflect the grpc bump Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(fixes): document atmos_vendor_pull DNS-resolution CI flake Acceptance Tests (macos, shard 4/10) failed with "tty did not match pattern \"Vendored 3 components\"" because git itself could not resolve github.com on the runner (OS-level resolver failure, corroborated by the same job's Harden Runner network log) -- not a code regression. No code change; re-running the job is expected to pass. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix: address CodeRabbit review findings on mocks docs, fix-logs, and noticegen tests - agent-skills/skills/atmos-migration/references/from-terragrunt.md: correct the mock_outputs -> mocks migration guidance -- Terragrunt scopes mock_outputs per dependency consumer, Atmos scopes mocks per producer component (shared by every consumer). Document that a shared mock value only works when every consumer agrees on it, and that a genuinely different per-consumer value needs its own producer component instance. - docs/fixes/2026-08-31-notice-go-licenses-install-retry.md: the retry loop now lives in tools/noticegen/report.go's ensureGoLicenses (tested in tools/noticegen/report_test.go), not scripts/generate-notice.sh, which was deleted when the NOTICE generator was rewritten as a Go tool. Updated the title, Context, Changes, and Validation sections accordingly. - docs/fixes/2026-08-31-required-check-gates-fail-on-cancelled-run.md: reworded "passing (all-steps-skipped) job" to "a passing job whose verification steps are skipped" -- the explicit Skip verification step still runs, so the job isn't literally all-skipped. - tools/noticegen/report.go: extracted lookPathGoLicenses as a package-level var (previously a direct exec.LookPath call inside ensureGoLicenses) so tests can force the "not found" branch deterministically. - tools/noticegen/report_test.go: both retry tests now inject lookPathGoLicenses to return exec.ErrNotFound, instead of relying on the real PATH not already containing go-licenses -- which it may, e.g. from a prior local run, silently skipping runGoInstall and making the retry assertions vacuous. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix: address CodeRabbit findings on SKILL.md link casing and vendor-pull fix-log wording - agent-skills/skills/atmos-migration/SKILL.md: lowercase the from-terragrunt.md reference link's display text to match the actual lowercase repo path and the style of the overview section's own link. - docs/fixes/2026-09-02-vendor-pull-dns-resolution-flake.md: correct the fixture description -- tests/fixtures/scenarios/vendor/vendor.yaml exercises a local file:// source and a git::https:// source, not an OCI source or a separate plain-HTTPS source. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(security): remediate 3 Dependabot/CodeQL alerts - golang.org/x/crypto v0.55.0 -> v0.56.0 (go get + go mod tidy), fixing two govulncheck alerts (GO-2026-6354, GO-2026-6355): a malicious SSH peer could deadlock a connection via crafted channel messages (golang.org/x/crypto/ssh). No direct callers in this repo beyond pkg/store/providers/github_actions_client.go; verified via go build and pkg/store/... tests. - website pnpm override: fast-uri@^3 -> ^3.1.6 (patched; published 10 days ago, clears this repo's 7-day minimum-release-age cooldown). - regenerate NOTICE to reflect the x/crypto bump. qs (Dependabot cloudposse#283/cloudposse#284, patched at 6.16.0) is intentionally NOT bumped: 6.16.0 was published 4 days ago, still inside website/.npmrc's 7-day minimum-release-age cooldown -- forcing it in via minimumReleaseAgeExclude would defeat the cooldown's purpose. Will pick it up once it clears. browserslist (cloudposse#281/cloudposse#282) and postcss-selector-parser (cloudposse#280) are already fixed on this branch from an earlier commit; GitHub just hasn't re-scanned yet. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(ci): whitelist go.googlesource.com/go.dev/pkg.go.dev for CodeQL Go jobs StepSecurity's blocked-call detections (analyzed via the stepsecurity MCP server) showed the analyze and govulncheck jobs' harden-runner egress policies blocking go.googlesource.com, go.dev, and pkg.go.dev during Go module/toolchain resolution -- both are trusted Go project domains (GOTOOLCHAIN auto-download and go-getter's git-host fallback path). go.googlesource.com was already allowed for govulncheck but missing from analyze; go.dev and pkg.go.dev were missing from both. Also removed a duplicate storage.googleapis.com entry in analyze's list. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: atmos-pro[bot] <173522224+atmos-pro[bot]@users.noreply.github.com> Co-authored-by: Andriy Knysh <aknysh@users.noreply.github.com>
zack-is-cool
pushed a commit
to zack-is-cool/atmos
that referenced
this pull request
Sep 8, 2026
…udposse#3010) * fix(store): don't fail the whole registry build on one bad store NewStoreRegistry aborted the entire stores: config load if a single store failed to resolve or construct, even one nothing referenced -- one misconfigured store took down every store, every remote-state lookup, and (transitively) every subcommand's config load. The kind not found error also omitted the store name, making a multi-store config hard to triage from the log alone. A store that fails to resolve (unknown kind), fails a secret/kind validation, or fails to construct is now skipped and logged as a named warning instead of returned as a fatal error. Code that actually looks up a skipped store by name still gets a clear error at the point of use. Closes cloudposse#2930 * fix(store): correct grammar in NewStoreRegistry doc comment Addresses CodeRabbit review feedback on PR cloudposse#3010. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(security): bump qs to 6.16.0, fixing GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g Dependabot alerts cloudposse#283/cloudposse#284: the website/pnpm.overrides pin for the transitive qs dependency (via docusaurus -> webpack-dev-server -> express) was capped at ^6.15.2, keeping it on the vulnerable 6.15.3. Both advisories are fixed in 6.16.0, a minor bump allowed by dependabot.yml's major-version ignore policy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps github.com/open-policy-agent/opa from 0.47.3 to 0.47.4.
Release notes
Sourced from github.com/open-policy-agent/opa's releases.
Changelog
Sourced from github.com/open-policy-agent/opa's changelog.
Commits
9b7c1c3Prepare v0.47.4 releaseaba5e3atester/runner: Fix panic'ing case in utility function. (#5497)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)