mirror of
https://github.com/drone-plugins/github-actions
synced 2026-10-07 13:12:03 +02:00
* fix: [CI-23943]: remediate github-actions image vulnerabilities Upgrade the Go toolchain, dependencies, Docker base image, and act runtime to reduce vulnerabilities while preserving plugin behavior. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: [CI-23943]: generate valid workflows for act Skip invalid placeholder output steps so actions without outputs remain compatible with newer act validation. Co-authored-by: Cursor <cursoragent@cursor.com> * fix: [CI-23943]: skip invalid env var names in act env file Harness injects a step's output variables into later steps in the stage (e.g. cache-hit and node-version from actions/setup-node). Hyphenated names are not valid in dotenv files, and act >= 0.2.89 fails to parse --env-file when they are present: Error loading from /tmp/action.env: unexpected character "-" in variable name near "cache-hit=..." Filter out any name that is not a valid dotenv identifier when writing the env file. Secrets handling and PLUGIN_* exclusion are unchanged. Found during HHI migration smoke testing (CI-24652) with harnesssecure/github-actions built on custom-ci-dind-base:29.8 (act 0.2.89). Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>