Conversation
- Pin all actions to commit SHAs and add per-job permissions - Run jobs on ubuntu-x64 with a repository_owner guard - Replace amannn/action-semantic-pull-request with twilio/sdk-actions/semantic-pr-title - Replace sendgrid/dx-automator release action with twilio/sdk-actions/github-release - Comment out Slack failure notifications and the Datadog release metric - Remove update-dependencies workflow in favour of Dependabot (maven + github-actions) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The sendgrid org allowlist only permits GitHub-owned actions, so docker/login-action caused a startup_failure for the whole workflow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
kridai
added this pull request to stack #787
October 6, 2026 08:31
shrutiburman
reviewed
Oct 6, 2026
|
|
||
| - name: Create GitHub Release | ||
| uses: sendgrid/dx-automator/actions/release@main | ||
| uses: twilio/sdk-actions/github-release@9b1c3222c9ffe38aadedb11c5b9f5a172b5e9951 # v1 |
Contributor
There was a problem hiding this comment.
fyi- the changelog generation is different in sdk-actions
shrutiburman
reviewed
Oct 6, 2026
| @@ -0,0 +1,10 @@ | |||
| version: 2 | |||
Contributor
There was a problem hiding this comment.
maybe verify after merge if dependabot even executes?
shrutiburman
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Ticket: https://twilio-engineering.atlassian.net/browse/DII-2643
Brings sendgrid-java's workflows in line with the platform team requirements already applied in twilio sdk
Changes
github-actions) keeps the pins current.permissions:contents: readfor tests,contents: writefor the deploy job, which creates the GitHub Release.ubuntu-x64, with anif: github.repository_owner == 'sendgrid'guard on test/deploy.amannn/action-semantic-pull-requestreplaced bytwilio/sdk-actions/semantic-pr-title. The types list changed from space-separated to newline-separated, because the new action splits only on commas and newlines.sendgrid/dx-automator/actions/releasereplaced bytwilio/sdk-actions/github-release. This needed three changes:fetch-depth: 0, because the action checks for the tag locally.changelog-file: CHANGELOG.md, because the action defaults toCHANGES.md.${version}replaced with${{ github.ref_name }}, because the new action doesn't substitute placeholders.-rctags are now marked as GitHub prereleases (prerelease: auto).sdk-actionsreplacement.update-dependencies.yml. Every scheduled run since at least 2026-08-11 ended instartup_failure, and it never landed a commit. Maven updates now come from Dependabot as reviewable PRs. This also drops theSG_JAVA_GITHUB_TOKENPAT, which can be revoked after merge.Not changed
central-publishing-maven-plugin0.8.0 with the same config as twilio-java, and the plugin targets Java 8, so publishing stays on JDK 8.Testing
actionlintreports only the expected "unknown label" warning for the self-hostedubuntu-x64label.sudo apt-get install -y docker-compose, which this PR's run will check on theubuntu-x64image.🤖 Generated with Claude Code