Repository navigation
chore(deps): update flatt-security/setup-takumi-guard-pypi action to v1.3.0 - #201
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/flatt-security-setup-takumi-guard-pypi-1.x
branch
from
September 29, 2026 10:58
2959d6b to
5883f08
Compare
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
renovate
Bot
force-pushed
the
renovate/flatt-security-setup-takumi-guard-pypi-1.x
branch
from
October 1, 2026 00:50
5883f08 to
84ecebc
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.0.1→v1.3.0Release Notes
flatt-security/setup-takumi-guard-pypi (flatt-security/setup-takumi-guard-pypi)
v1.3.0Compare Source
What changed
PIP_INDEX_URLandUV_INDEX_URL, which poetry does not read, so poetry reached Takumi Guard without it. poetry now takes it from a job.netrcfor every source onpypi.flatt.tech, whatever the source is named..netrcfor the job only. It goes to$RUNNER_TEMP/.netrc, which the runner empties at the start and end of every job, andNETRCpoints to it for the rest of the job. The file starts as a copy of your existing one (the fileNETRCnames, else~/.netrc, else~/_netrc), so entries for other hosts keep working.~/.netrcis not modified, so no token is left on a self-hosted runner and concurrent jobs keep their own bot.UV_INDEX_<NAME>_USERNAME/PASSWORDis set for each uv index inpyproject.tomlanduv.tomlin the checkout that points at Takumi Guard, and for the newuv-index-nameinput (defaulttakumi-guard) to cover an index the action cannot see. A name that any index in the checkout uses for another host gets no token, and the action reports it.set-index-url: false, the action no longer setsPIP_INDEX_URLandUV_INDEX_URL. An index variable you set that already points at Takumi Guard gets the token added.--index-url/--extra-index-urlin a requirements file, orPIP_EXTRA_INDEX_URL/UV_EXTRA_INDEX_URLthat points elsewhere produces a warning. An explicit index, which serves only the packages assigned to it, is not reported.PIP_INDEX_URL(unchanged), and the job.netrc.netrc;PIP_INDEX_URLalready pointing at Takumi Guard gets the token.netrc(was anonymous).netrc(was anonymous)UV_INDEX_URL(unchanged), and named credentialsUV_INDEX_URL/UV_DEFAULT_INDEXalready pointing at Takumi Guard get the token; named credentialsBehaviour changes for existing workflows
PIP_INDEX_URLandUV_INDEX_URLto Takumi Guard after authenticating, even withset-index-url: false. Point pip, uv or poetry athttps://pypi.flatt.tech/simple/in your own configuration to keep installs going through Takumi Guard.NETRCis set for the rest of the job. A later step that writes to~/.netrchas no effect; write to$NETRCinstead. This includes setup-takumi-guard-golang: run it before this action, or Go downloads go through Takumi Guard without the token.actions/checkoutso it can read the project's configuration.v1.2.0Compare Source
What changed
bot-idset, a missingid-token: writepermission, a failed OIDC request or an STS refusal used to print an error annotation and continue withPIP_INDEX_URLandUV_INDEX_URLalready set without a token, so later installs reached Takumi Guard anonymously while the job stayed green. The step now exits with an error regardless ofset-index-url. Omittingbot-idstill runs in anonymous mode.Could not reach the STS at <url>., and a response that is not JSON, such as an HTML error page, fails withSTS returned non-JSON (HTTP <code>).followed by the start of the response in the log.bot-idset)permissions: { id-token: write }OIDC not available. Add 'permissions: { id-token: write }' to your job.Failed to get OIDC token.Authentication failed: <STS message>Could not reach the STS at <url>.STS returned non-JSON (HTTP <code>).bot-idomittedBehaviour changes for existing workflows
A workflow that sets
bot-idbut does not authenticate today fails at this step:permissions: { id-token: write }. Add it to the job.bot-idfor those runs.To run without a bot, omit
bot-id.v1.1.0Compare Source
New Feature
audienceinput controls theaudclaim of the OIDC token requested for the bot token exchange. (#3)audchange: withaudienceunset, the token is now requested with the STS URL (https://sts.cloud.shisho.dev, normalized without a trailing slash) as its audience — previously the hardcoded registry hostpypi.flatt.tech. Built-in trust conditions do not validateaud, so existing setups are unaffected; CustomOIDC trust conditions using the default STS audience (e.g. GitHub Enterprise Server) start working without overrides.audienceexplicitly if your Bot trust condition expects a different value.Note:
v1has not moved yet — workflows trackingv1keep the previous behavior until the upcomingv1retag. Pinned tags are unaffected.Configuration
📅 Schedule: (in timezone Asia/Tokyo)
* 20-23 * * 1-5)* 9-21 * * 0,6)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.