From 4fce9117a8310c2caea785e9860dc92d77483c98 Mon Sep 17 00:00:00 2001 From: Cody Spath Date: Wed, 30 Sep 2026 10:15:11 -0400 Subject: [PATCH] prepare 2.3.3 release Releases two changes that have been sitting on main: #253 retry rate-limited flag requests, and preserve cancellation and timeout errors while reading flag responses #255 pelletier/go-toml/v2 to v2.4.3 (XRAY-1033007) Patch rather than minor: #253 is retry and error-propagation behaviour, which the contributor filed under Fixed, and no inputs or outputs changed. Two corrections to repository bookkeeping while here: The version constant was still 2.3.1. v2.3.2 was tagged directly at the #254 merge commit without a prepare-release commit, so the constant and the metadata pins never moved. Both are now at 2.3.3. The changelog had no 2.3.2 entry for the same reason, even though v2.3.2 was a real release that Gonfalon pins. Backfilled it from #254. Also floats the docker/ entry point example on `@v2` to match the two root Action examples above it, which already used `@v2`. That line no longer needs rewriting each release, and the "pin to a release that includes the docker/ entry point" caveat is obsolete now it floats. The `dockerImage` input keeps an exact tag. Co-Authored-By: Claude Opus 5 --- CHANGELOG.md | 11 +++++++++++ README.md | 5 ++--- docker/action.yml | 4 ++-- internal/version/version.go | 2 +- 4 files changed, 16 insertions(+), 6 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3824360a..7ac0daf5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,8 +6,19 @@ ### Fixed +## 2.3.3 + +### Fixed + - Retry rate-limited feature flag requests using applicable quota reset times and `Retry-After` - Preserve cancellation and timeout errors while reading feature flag responses +- Bumped `github.com/pelletier/go-toml/v2` to v2.4.3, clearing a reported denial-of-service finding (XRAY-1033007). The module arrives indirectly through `spf13/viper`; the upstream release bounds array and inline-table nesting depth to prevent a stack-overflow crash + +## 2.3.2 + +### Changed + +- Pinned the Go toolchain to 1.26.8 via a `toolchain` directive and bumped `ld-find-code-refs` to v2.18.1 along with `x/crypto`, `x/text` and `go-git`, clearing 22 reachable standard library vulnerabilities and 8 in imported packages. The builder image is pinned to `golang:1.26.8-alpine` instead of the floating `golang:alpine`, and the runtime base moves from `alpine:3.21` to `alpine:3.24.2` ## 2.3.1 diff --git a/README.md b/README.md index 5103a428..2c72c87a 100644 --- a/README.md +++ b/README.md @@ -108,14 +108,13 @@ jobs: password: ${{ secrets.REGISTRY_TOKEN }} - name: Find flags id: find-flags - # Pin to a release that includes the docker/ entry point and published image (see changelog). - uses: launchdarkly/find-code-references-in-pull-request/docker@v2.3.1 + uses: launchdarkly/find-code-references-in-pull-request/docker@v2 with: project-key: default environment-key: production access-token: ${{ secrets.LD_ACCESS_TOKEN }} repo-token: ${{ secrets.GITHUB_TOKEN }} - dockerImage: your.registry.example/launchdarkly/find-code-references-in-pull-request:2.3.1 + dockerImage: your.registry.example/launchdarkly/find-code-references-in-pull-request:2.3.3 ``` This entry point requires a Docker CLI on the runner (included on GitHub-hosted `ubuntu-*` runners). Existing workflows that use the root Action do not need to change. diff --git a/docker/action.yml b/docker/action.yml index 06f6ea15..8401c8f6 100644 --- a/docker/action.yml +++ b/docker/action.yml @@ -55,12 +55,12 @@ inputs: description: >- Container image to run. Defaults to the public Docker Hub runtime image. Set this to your mirrored/proxy image (for example - your.registry.example/launchdarkly/find-code-references-in-pull-request:2.3.1). + your.registry.example/launchdarkly/find-code-references-in-pull-request:2.3.3). Authenticate to private registries with docker/login-action (or equivalent) in a prior step. Requires a runner with a Docker CLI (GitHub-hosted ubuntu-* runners include one). required: false - default: "launchdarkly/find-code-references-in-pull-request:2.3.1" + default: "launchdarkly/find-code-references-in-pull-request:2.3.3" outputs: any-modified: diff --git a/internal/version/version.go b/internal/version/version.go index fd2e2a4c..62c65bf1 100644 --- a/internal/version/version.go +++ b/internal/version/version.go @@ -1,3 +1,3 @@ package version -const Version = "2.3.1" +const Version = "2.3.3"