Skip to content

Commit 835aec3

Browse files
authored
Merge branch 'main' into renovate/all-go-dependencies
2 parents 7ce4a7a + c299f62 commit 835aec3

File tree

5 files changed

+48
-4
lines changed

5 files changed

+48
-4
lines changed
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
name: renovate-auto-approve
2+
3+
on:
4+
pull_request_target:
5+
types:
6+
- opened
7+
- reopened
8+
- review_requested
9+
- synchronize
10+
jobs:
11+
renovate-auto-approve:
12+
runs-on: ubuntu-latest
13+
permissions:
14+
pull-requests: write
15+
id-token: write
16+
if: github.actor == 'renovate[bot]' && startsWith(github.head_ref, 'renovate/')
17+
steps:
18+
- name: Configure Workload Identity Federation
19+
id: auth
20+
uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 # v3
21+
with:
22+
project_id: ${{ vars.GCP_KYMA_PROJECT_PROJECT_ID }}
23+
workload_identity_provider: ${{ vars.GH_COM_KYMA_PROJECT_GCP_WORKLOAD_IDENTITY_FEDERATION_PROVIDER }}
24+
25+
- name: Fetch Kyma Bot Token For Auto Approve
26+
id: access-secret
27+
uses: google-github-actions/get-secretmanager-secrets@bc9c54b29fdffb8a47776820a7d26e77b379d262 # v3
28+
with:
29+
secrets: |
30+
GITHUB_TOKEN:${{ vars.GCP_KYMA_PROJECT_PROJECT_ID }}/${{ vars.GH_COM_KYMA_BOT_AUTO_APPROVER_TOKEN_SECRET_NAME }}
31+
32+
- name: Auto Approve PR
33+
uses: hmarr/auto-approve-action@f0939ea97e9205ef24d872e76833fa908a770363 # v4
34+
with:
35+
review-message: "Auto approval of PR generated by Renovate Bot"
36+
github-token: ${{ steps.access-secret.outputs.GITHUB_TOKEN }}
37+
38+
- name: Add auto-approved Label to PR
39+
run: gh pr edit "$NUMBER" --add-label "$LABELS"
40+
env:
41+
GH_REPO: ${{ github.repository }}
42+
GH_TOKEN: ${{ steps.access-secret.outputs.GITHUB_TOKEN }}
43+
NUMBER: ${{ github.event.pull_request.number }}
44+
LABELS: auto-approved

.tflint.hcl

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ config {
99

1010
plugin "google" {
1111
enabled = true
12-
version = "0.35.0"
12+
version = "0.36.0"
1313
source = "github.com/terraform-linters/tflint-ruleset-google"
1414
}
1515

cmd/cloud-run/slackmessagesender/requirements.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,5 +4,5 @@ flask>=2.3.2
44
cloudevents==1.12.0
55
gunicorn==23.0.0
66
pygithub==2.8.1
7-
pyyaml==6.0.2
7+
pyyaml==6.0.3
88
werkzeug>=3.0.6

configs/terraform/modules/slack-message-sender/slack-message-sender.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ resource "google_cloud_run_service" "slack_message_sender" {
3838
spec {
3939
service_account_name = google_service_account.slack_message_sender.email
4040
containers {
41-
image = "europe-docker.pkg.dev/kyma-project/prod/test-infra/slackmessagesender:v20250910-77a3f821"
41+
image = "europe-docker.pkg.dev/kyma-project/prod/test-infra/slackmessagesender:v20250925-ea9d9cf9"
4242
env {
4343
name = "PROJECT_ID"
4444
value = var.gcp_project_id

sec-scanners-config.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ bdba:
77
- europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20250924-935a21c6
88
- europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20250924-935a21c6
99
- europe-docker.pkg.dev/kyma-project/prod/test-infra/signify-secret-rotator:v20250917-e51a4bba
10-
- europe-docker.pkg.dev/kyma-project/prod/test-infra/slackmessagesender:v20250910-77a3f821
10+
- europe-docker.pkg.dev/kyma-project/prod/test-infra/slackmessagesender:v20250925-ea9d9cf9
1111
mend:
1212
language: golang-mod
1313
exclude:

0 commit comments

Comments
 (0)