Files
Bussa Aditya Naga Sai LaxmanandCursor 7f3c946f42 fix: [CI-23943]: make plugin compatible with act 0.2.89 (#32)
* fix: [CI-23943]: remediate github-actions image vulnerabilities

Upgrade the Go toolchain, dependencies, Docker base image, and act runtime to reduce vulnerabilities while preserving plugin behavior.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: [CI-23943]: generate valid workflows for act

Skip invalid placeholder output steps so actions without outputs remain compatible with newer act validation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: [CI-23943]: skip invalid env var names in act env file

Harness injects a step's output variables into later steps in the stage
(e.g. cache-hit and node-version from actions/setup-node). Hyphenated
names are not valid in dotenv files, and act >= 0.2.89 fails to parse
--env-file when they are present:

  Error loading from /tmp/action.env: unexpected character "-" in
  variable name near "cache-hit=..."

Filter out any name that is not a valid dotenv identifier when writing
the env file. Secrets handling and PLUGIN_* exclusion are unchanged.

Found during HHI migration smoke testing (CI-24652) with
harnesssecure/github-actions built on custom-ci-dind-base:29.8
(act 0.2.89).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-17 21:04:55 +05:30
..