Skip to content

Bug fixes and wrapper bump version to 2.4.24#445

Open
cx-atish-jadhav wants to merge 15 commits into
mainfrom
other/release-integration
Open

Bug fixes and wrapper bump version to 2.4.24#445
cx-atish-jadhav wants to merge 15 commits into
mainfrom
other/release-integration

Conversation

@cx-atish-jadhav

Copy link
Copy Markdown
Collaborator

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change.

References

Include supporting link to GitHub Issue/PR number

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

  • I have added documentation for new/changed functionality in this PR (if applicable).
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used

cx-atish-jadhav and others added 5 commits May 26, 2026 19:03
commit 1a82281
Author: atishj99 <141334503+cx-atish-jadhav@users.noreply.github.com>
Date:   Fri May 29 14:29:02 2026 +0530

    bug fixes and claude.md changes

commit 484b0c1
Author: atishj99 <141334503+cx-atish-jadhav@users.noreply.github.com>
Date:   Mon Apr 20 14:47:43 2026 +0530

    Add CLAUDE.md for ast-jetbrains-plugin
@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Actions Policy Violation

This workflow run has been blocked by StepSecurity's actions policy.

Disallowed Actions:

  • timonvs/pr-labeler-action@8b99f404a073744885d8021d1de4e40c6eaf38e2

To fix this issue, please modify the workflow to use only allowed actions. Contact your organization administrator to request changes to the allowed actions list if needed.

For more information, see StepSecurity's Actions Policy documentation.

@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.PERSONAL_ACCESS_TOKEN at line 15

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-atish-jadhav) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

cx-luis-ventuzelos and others added 5 commits June 23, 2026 18:48
- Add workflow-level permissions: contents: read to all workflows
- Add job-level permissions scoped to minimum required
- Move all ${{ inputs.* }} and ${{ needs.*.outputs.* }} to env: vars in run steps to prevent script injection
- Replace disallowed dev-drprasad/delete-older-releases with gh release delete loop
- Comment out TimonVS/pr-labeler-action (disallowed action)
- Comment out notify and dispatch jobs calling plugins-release-workflow
- Comment out auto-merge, dependabot-auto-merge, nightly, and update-wrapper-version jobs
- Comment out issue-automation Jira jobs
- Remove repository_dispatch trigger from update-wrapper-version
- Add persist-credentials: false to all read-only checkout steps
- Fix env.CLI_VERSION inline injection in release job outputs step
- Change publish input default from true to false
- Replace dev-drprasad/delete-older-releases with gh release delete

@cx-anurag-dalke cx-anurag-dalke left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok

cx-nisan-benabu and others added 2 commits June 24, 2026 13:59
The StepSecurity Policy Store policy on the cx-public-ubuntu-x64 runners
was force-canceling every job. Add a SHA-pinned harden-runner step in
audit (non-blocking) mode as the first step of each CI/scan job.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants