mirror of
https://github.com/drone-plugins/github-actions
synced 2026-10-07 04:03:37 +02:00
main
* fix: [CI-23943]: remediate github-actions image vulnerabilities Upgrade the Go toolchain, dependencies, Docker base image, and act runtime to reduce vulnerabilities while preserving plugin behavior. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: [CI-23943]: generate valid workflows for act Skip invalid placeholder output steps so actions without outputs remain compatible with newer act validation. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: [CI-23943]: skip invalid env var names in act env file Harness injects a step's output variables into later steps in the stage (e.g. cache-hit and node-version from actions/setup-node). Hyphenated names are not valid in dotenv files, and act >= 0.2.89 fails to parse --env-file when they are present: Error loading from /tmp/action.env: unexpected character "-" in variable name near "cache-hit=..." Filter out any name that is not a valid dotenv identifier when writing the env file. Secrets handling and PLUGIN_* exclusion are unchanged. Found during HHI migration smoke testing (CI-24652) with harnesssecure/github-actions built on custom-ci-dind-base:29.8 (act 0.2.89). Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
drone-github-action-plugin
This plugin allows running github actions as a drone plugin.
Build
Build the binaries with the following commands:
export GOOS=linux
export GOARCH=amd64
export CGO_ENABLED=0
export GO111MODULE=on
go build -v -a -tags netgo -o release/linux/amd64/plugin ./cmd
Docker
Build the Docker images with the following commands:
docker build \
--label org.label-schema.build-date=$(date -u +"%Y-%m-%dT%H:%M:%SZ") \
--label org.label-schema.vcs-ref=$(git rev-parse --short HEAD) \
--file docker/Dockerfile.linux.amd64 --tag plugins/github-actions .
Plugin step usage
Provide uses, with & env of github action to use in plugin step settings. Provide GITHUB_TOKEN as environment variable if it is required for an action.
steps:
- name: github-action
image: plugins/github-actions
settings:
uses: actions/hello-world-javascript-action@v1.1
with:
who-to-greet: Mona the Octocat
env:
hello: world
Running locally
- If you are running it on mac locally & /var/run/docker.sock file does not exist, first run this command
ln -s ~/.docker/run/docker.sock /var/run/docker.sock - Running actions/hello-world-javascript-action action locally via docker:
docker run --rm \
--privileged \
-v $(pwd):/drone \
-w /drone \
-e PLUGIN_USES="actions/hello-world-javascript-action@v1.1" \
-e PLUGIN_WITH="{\"who-to-greet\":\"Mona the Octocat\"}" \
-e PLUGIN_VERBOSE=true \
plugins/github-actions
Languages
Go
99.1%
Shell
0.9%