From 7c03a39060ddc193a70a4eb7bd47e8e8ba21a801 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 24 Aug 2026 01:32:07 +0000 Subject: [PATCH 1/3] Bump github.com/sirupsen/logrus from 1.8.1 to 1.8.3 Bumps [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus) from 1.8.1 to 1.8.3. - [Release notes](https://github.com/sirupsen/logrus/releases) - [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md) - [Commits](https://github.com/sirupsen/logrus/compare/v1.8.1...v1.8.3) --- updated-dependencies: - dependency-name: github.com/sirupsen/logrus dependency-version: 1.8.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- go.mod | 2 +- go.sum | 5 +++-- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 6024d1dd..6e53aaea 100644 --- a/go.mod +++ b/go.mod @@ -3,7 +3,7 @@ module github.com/stackql/stackql-provider-registry go 1.17 require ( - github.com/sirupsen/logrus v1.8.1 + github.com/sirupsen/logrus v1.8.3 github.com/spf13/cobra v1.4.0 github.com/spf13/viper v1.10.1 gotest.tools v2.2.0+incompatible diff --git a/go.sum b/go.sum index 4c150275..121bd874 100644 --- a/go.sum +++ b/go.sum @@ -306,8 +306,8 @@ github.com/sagikazarmark/crypt v0.4.0/go.mod h1:ALv2SRj7GxYV4HO9elxH9nS6M9gW+xDN github.com/sean-/seed v0.0.0-20170313163322-e2103e2c3529/go.mod h1:DxrIzT+xaE7yg65j358z/aeFdxmN0P9QXhEzd20vsDc= github.com/sirupsen/logrus v1.2.0/go.mod h1:LxeOpSwHxABJmUn/MG1IvRgCAasNZTLOkJPxbbu5VWo= github.com/sirupsen/logrus v1.4.2/go.mod h1:tLMulIdttU9McNUspp0xgXVQah82FyeX6MwdIuYE2rE= -github.com/sirupsen/logrus v1.8.1 h1:dJKuHgqk1NNQlqoA6BTlM1Wf9DOH3NBjQyu0h9+AZZE= -github.com/sirupsen/logrus v1.8.1/go.mod h1:yWOB1SBYBC5VeMP7gHvWumXLIWorT60ONWic61uBYv0= +github.com/sirupsen/logrus v1.8.3 h1:DBBfY8eMYazKEJHb3JKpSPfpgd2mBCoNFlQx6C5fftU= +github.com/sirupsen/logrus v1.8.3/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ= github.com/spaolacci/murmur3 v0.0.0-20180118202830-f09979ecbc72/go.mod h1:JwIasOWyU6f++ZhiEuf87xNszmSA2myDM2Kzu9HwQUA= github.com/spf13/afero v1.3.3/go.mod h1:5KUK8ByomD5Ti5Artl0RtHeI5pTF7MIDuXL3yY520V4= github.com/spf13/afero v1.6.0 h1:xoax2sJ2DT8S8xA2paPFjDCScCNeWsg75VG0DLRreiY= @@ -536,6 +536,7 @@ golang.org/x/sys v0.0.0-20211007075335-d3039528d8ac/go.mod h1:oPkhp1MJrh7nUepCBc golang.org/x/sys v0.0.0-20211124211545-fe61309f8881/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20211210111614-af8b64212486/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= +golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f h1:v4INt8xihDGvnrfjMDVXGxw9wrfxYyCjk0KbXjhR55s= golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo= From bfa1bec67ed55d4594e3e410529c958aec4cc4d3 Mon Sep 17 00:00:00 2001 From: Jeffrey Aven Date: Tue, 25 Aug 2026 07:52:50 +1000 Subject: [PATCH 2/3] ci: drop CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN from upstream checkouts stackql/stackql and stackql/any-sdk are public, so actions/checkout can clone them with the default GITHUB_TOKEN. The explicit PAT input broke Dependabot-triggered runs, which only see the Dependabot secret store ("Input required and not supplied: token"). Co-Authored-By: Claude Fable 5 --- .github/workflows/aot.yml | 2 -- .github/workflows/regression.yml | 3 --- 2 files changed, 5 deletions(-) diff --git a/.github/workflows/aot.yml b/.github/workflows/aot.yml index 32e7dfe4..a0c961ba 100644 --- a/.github/workflows/aot.yml +++ b/.github/workflows/aot.yml @@ -56,7 +56,6 @@ jobs: with: repository: ${{ env.STACKQL_CORE_REPOSITORY }} ref: ${{ env.STACKQL_CORE_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-core - name: Download any-sdk @@ -64,7 +63,6 @@ jobs: with: repository: ${{ env.STACKQL_ANY_SDK_REPOSITORY }} ref: ${{ env.STACKQL_ANY_SDK_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-any-sdk - name: Setup Python diff --git a/.github/workflows/regression.yml b/.github/workflows/regression.yml index 09b3e7ab..c7a043e3 100644 --- a/.github/workflows/regression.yml +++ b/.github/workflows/regression.yml @@ -35,7 +35,6 @@ jobs: with: repository: ${{ env.STACKQL_CORE_REPOSITORY }} ref: ${{ env.STACKQL_CORE_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-core-pkg - name: Setup Python @@ -100,7 +99,6 @@ jobs: with: repository: ${{ env.STACKQL_CORE_REPOSITORY }} ref: ${{ env.STACKQL_CORE_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-core - name: Download any-sdk @@ -108,7 +106,6 @@ jobs: with: repository: ${{ env.STACKQL_ANY_SDK_REPOSITORY }} ref: ${{ env.STACKQL_ANY_SDK_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-any-sdk - name: Setup Python From f2202acaaa8578c8f12e0d8000fbcbd730b89f34 Mon Sep 17 00:00:00 2001 From: Jeffrey Aven Date: Tue, 25 Aug 2026 07:58:03 +1000 Subject: [PATCH 3/3] ci: only publish/deploy registry artefacts when providers/src changed Gate every [PUBLISH] and [DEPLOY*] step in main.yml on NUM_PROVIDERS > 0 (derived from providers/src/ paths in diff.txt) in addition to the existing push/branch conditions. A merge to dev or main that touches nothing under providers/src/ now runs the [SETUP] steps only: no S3 publish, no R2 sync, no worker deploy. Co-Authored-By: Claude Fable 5 --- .github/workflows/main.yml | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 34a9a16d..6157dff2 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -126,11 +126,14 @@ jobs: # # run the following steps only on pushes to protected branches (merge commits) + # AND only when provider artefacts under providers/src/ changed (NUM_PROVIDERS > 0). + # A push that touches nothing under providers/src/ must never publish to S3, + # sync R2 or redeploy the worker. # - name: "[PUBLISH] configure aws credentials" uses: aws-actions/configure-aws-credentials@v6 - if: env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_EVENT == 'push' with: aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} @@ -142,7 +145,7 @@ jobs: python scripts/publish/publish-provider-docs-to-artifact-repo.py - name: "[DEPLOY] pull additional docs from artifact repo" - if: env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_EVENT == 'push' run: | python scripts/deploy/pull-additional-docs-from-artifact-repo.py @@ -156,12 +159,12 @@ jobs: # - name: "[DEPLOY-CF] install worker deps" - if: env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_EVENT == 'push' run: | cd origin && npm install - name: "[DEPLOY-CF] sync docs to R2 (dev)" - if: env.REG_TARGET_BRANCH == 'dev' && env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_TARGET_BRANCH == 'dev' && env.REG_EVENT == 'push' env: AWS_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }} @@ -180,7 +183,7 @@ jobs: --region auto --no-progress - name: "[DEPLOY-CF] sync docs to R2 (prod)" - if: env.REG_TARGET_BRANCH == 'main' && env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_TARGET_BRANCH == 'main' && env.REG_EVENT == 'push' env: AWS_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }} @@ -197,7 +200,7 @@ jobs: --no-progress - name: "[DEPLOY-CF] deploy worker (dev)" - if: env.REG_TARGET_BRANCH == 'dev' && env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_TARGET_BRANCH == 'dev' && env.REG_EVENT == 'push' env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} @@ -205,7 +208,7 @@ jobs: cd origin && npx wrangler deploy --env dev - name: "[DEPLOY-CF] deploy worker (prod)" - if: env.REG_TARGET_BRANCH == 'main' && env.REG_EVENT == 'push' + if: env.NUM_PROVIDERS > 0 && env.REG_TARGET_BRANCH == 'main' && env.REG_EVENT == 'push' env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}