From 51343179a04dfeafdccfbe0767b7937b2113ae05 Mon Sep 17 00:00:00 2001 From: Joyce Quach Date: Thu, 12 Dec 2024 17:48:40 -0500 Subject: [PATCH 1/4] Update workflow to use artifact actions v4 Signed-off-by: Joyce Quach --- .github/workflows/verify-s3.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/verify-s3.yml b/.github/workflows/verify-s3.yml index 76f7f9b..ad5e495 100644 --- a/.github/workflows/verify-s3.yml +++ b/.github/workflows/verify-s3.yml @@ -44,7 +44,7 @@ jobs: - name: Run Inspec test run: bundle exec inspec exec . --input single_bucket=${{ secrets.BUCKET_W_PUB_OBJ }} --auto-install-gems --target aws:// --reporter cli json:results.json || true - name: Save Test Result JSON - uses: actions/upload-artifact@v3 + uses: actions/upload-artifact@v4 with: path: ./results.json - name: Display our results summary From 9d711ac46b1925dea8fa64b8c82bd65d31688756 Mon Sep 17 00:00:00 2001 From: Joyce Quach Date: Thu, 26 Dec 2024 16:39:02 -0500 Subject: [PATCH 2/4] Update secrets used in verify-s3.yml Signed-off-by: Joyce Quach --- .github/workflows/verify-s3.yml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/verify-s3.yml b/.github/workflows/verify-s3.yml index ad5e495..2498d5e 100644 --- a/.github/workflows/verify-s3.yml +++ b/.github/workflows/verify-s3.yml @@ -18,13 +18,13 @@ jobs: run: sudo apt-get install -y jq - name: Configure AWS credentials env: - AWS_SG_ID: ${{ secrets.AWS_SG_ID }} - AWS_SUBNET_ID: ${{ secrets.AWS_SUBNET_ID }} + AWS_SG_ID: ${{ secrets.SAF_AWS_SG_ID }} + AWS_SUBNET_ID: ${{ secrets.SAF_AWS_SUBNET_ID }} uses: aws-actions/configure-aws-credentials@v1 with: - aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} - aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} - aws-region: us-east-1 + aws-access-key-id: ${{ secrets.SAF_AWS_ACCESS_KEY_ID }} + aws-secret-access-key: ${{ secrets.SAF_AWS_SECRET_ACCESS_KEY }} + aws-region: ${{ secrets.SAF_AWS_REGION }} - name: Check out repository uses: actions/checkout@v2 - name: Clone full repository so we can push @@ -32,7 +32,7 @@ jobs: - name: Setup Ruby uses: ruby/setup-ruby@v1 with: - ruby-version: "3.1.2" + ruby-version: '3.1.2' - name: Disable ri and rdoc run: 'echo "gem: --no-ri --no-rdoc" >> ~/.gemrc' - name: Bundle install gems @@ -50,8 +50,8 @@ jobs: - name: Display our results summary uses: mitre/saf_action@v1 with: - command_string: "view:summary -i results.json" + command_string: 'view:summary -i results.json' - name: Ensure the scan meets our results threshold uses: mitre/saf_action@v1 with: - command_string: "validate:threshold -i results.json -F threshold.yml" + command_string: 'validate:threshold -i results.json -F threshold.yml' From 1e9dcd7fe9a62e87290c5dabd60221d333e03dca Mon Sep 17 00:00:00 2001 From: Joyce Quach Date: Thu, 26 Dec 2024 16:44:04 -0500 Subject: [PATCH 3/4] Revert change to access key id and secret access key Signed-off-by: Joyce Quach --- .github/workflows/verify-s3.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/verify-s3.yml b/.github/workflows/verify-s3.yml index 2498d5e..9d15979 100644 --- a/.github/workflows/verify-s3.yml +++ b/.github/workflows/verify-s3.yml @@ -22,8 +22,8 @@ jobs: AWS_SUBNET_ID: ${{ secrets.SAF_AWS_SUBNET_ID }} uses: aws-actions/configure-aws-credentials@v1 with: - aws-access-key-id: ${{ secrets.SAF_AWS_ACCESS_KEY_ID }} - aws-secret-access-key: ${{ secrets.SAF_AWS_SECRET_ACCESS_KEY }} + aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} + aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} aws-region: ${{ secrets.SAF_AWS_REGION }} - name: Check out repository uses: actions/checkout@v2 From cab8dcc2fc6b4099593d425f4ede4534ccd27e21 Mon Sep 17 00:00:00 2001 From: Joyce Quach Date: Thu, 26 Dec 2024 17:13:16 -0500 Subject: [PATCH 4/4] Update secrets used in verify-s3.yml again Signed-off-by: Joyce Quach --- .github/workflows/verify-s3.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/verify-s3.yml b/.github/workflows/verify-s3.yml index 9d15979..2498d5e 100644 --- a/.github/workflows/verify-s3.yml +++ b/.github/workflows/verify-s3.yml @@ -22,8 +22,8 @@ jobs: AWS_SUBNET_ID: ${{ secrets.SAF_AWS_SUBNET_ID }} uses: aws-actions/configure-aws-credentials@v1 with: - aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} - aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} + aws-access-key-id: ${{ secrets.SAF_AWS_ACCESS_KEY_ID }} + aws-secret-access-key: ${{ secrets.SAF_AWS_SECRET_ACCESS_KEY }} aws-region: ${{ secrets.SAF_AWS_REGION }} - name: Check out repository uses: actions/checkout@v2