Skip to content

chore: harden GitHub Actions for platform compliance - #785

Open
kridai wants to merge 3 commits into
mainfrom
chore/harden-github-actions
Open

kridai wants to merge 3 commits into
mainfrom
chore/harden-github-actions

Conversation

@kridai

@kridai kridai commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

Ticket: https://twilio-engineering.atlassian.net/browse/DII-2643
Brings sendgrid-java's workflows in line with the platform team requirements already applied in twilio sdk

Changes

  • All actions pinned to commit SHAs, with version comments. Dependabot (github-actions) keeps the pins current.
  • Per-job permissions: contents: read for tests, contents: write for the deploy job, which creates the GitHub Release.
  • Runner: every job moved to ubuntu-x64, with an if: github.repository_owner == 'sendgrid' guard on test/deploy.
  • PR title lint: amannn/action-semantic-pull-request replaced by twilio/sdk-actions/semantic-pr-title. The types list changed from space-separated to newline-separated, because the new action splits only on commas and newlines.
  • GitHub Release: sendgrid/dx-automator/actions/release replaced by twilio/sdk-actions/github-release. This needed three changes:
    • fetch-depth: 0, because the action checks for the tag locally.
    • changelog-file: CHANGELOG.md, because the action defaults to CHANGES.md.
    • The footer's ${version} replaced with ${{ github.ref_name }}, because the new action doesn't substitute placeholders.
    • Side effect: -rc tags are now marked as GitHub prereleases (prerelease: auto).
  • Commented out: Slack failure notifications and the Datadog release metric. They use actions that aren't allowlisted and have no sdk-actions replacement.
  • Removed update-dependencies.yml. Every scheduled run since at least 2026-08-11 ended in startup_failure, and it never landed a commit. Maven updates now come from Dependabot as reviewable PRs. This also drops the SG_JAVA_GITHUB_TOKEN PAT, which can be revoked after merge.

Not changed

  • The Maven Central publish step. The pom already uses central-publishing-maven-plugin 0.8.0 with the same config as twilio-java, and the plugin targets Java 8, so publishing stays on JDK 8.

Testing

  • All files parse as YAML. actionlint reports only the expected "unknown label" warning for the self-hosted ubuntu-x64 label.
  • Every pinned SHA was resolved against the upstream repos.
  • Not yet run in CI. The test job still runs sudo apt-get install -y docker-compose, which this PR's run will check on the ubuntu-x64 image.

🤖 Generated with Claude Code

- Pin all actions to commit SHAs and add per-job permissions
- Run jobs on ubuntu-x64 with a repository_owner guard
- Replace amannn/action-semantic-pull-request with twilio/sdk-actions/semantic-pr-title
- Replace sendgrid/dx-automator release action with twilio/sdk-actions/github-release
- Comment out Slack failure notifications and the Datadog release metric
- Remove update-dependencies workflow in favour of Dependabot (maven + github-actions)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
kridai and others added 2 commits October 5, 2026 14:23
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The sendgrid org allowlist only permits GitHub-owned actions, so
docker/login-action caused a startup_failure for the whole workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

- name: Create GitHub Release
uses: sendgrid/dx-automator/actions/release@main
uses: twilio/sdk-actions/github-release@9b1c3222c9ffe38aadedb11c5b9f5a172b5e9951 # v1

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fyi- the changelog generation is different in sdk-actions

Comment thread .github/dependabot.yml
@@ -0,0 +1,10 @@
version: 2

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

maybe verify after merge if dependabot even executes?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants