Skip to content

Test infra plan/apply with multiple projects#354

Draft
mamu0 wants to merge 16 commits into
mainfrom
test-infra-apply-matrix
Draft

Test infra plan/apply with multiple projects#354
mamu0 wants to merge 16 commits into
mainfrom
test-infra-apply-matrix

fix: test plan mode if _modules changed

b360110
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 2, 2026 in 4s

19 new alerts including 19 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 19 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 66 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 62 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step: get-version
uses 'pagopa/dx/.github/actions/get-terraform-version' with ref 'main', not a pinned commit hash

Check warning on line 134 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 150 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Check warning on line 210 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step
uses 'pagopa/dx/actions/csp-login' with ref 'main', not a pinned commit hash

Check warning on line 213 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step: set-terraform-version
uses 'pagopa/dx/.github/actions/terraform-setup' with ref 'main', not a pinned commit hash

Check warning on line 238 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step: upload_plan
uses 'pagopa/dx/actions/terraform-plan-storage-upload' with ref 'main', not a pinned commit hash

Check warning on line 304 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step
uses 'pagopa/dx/actions/csp-login' with ref 'main', not a pinned commit hash

Check warning on line 307 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step
uses 'pagopa/dx/.github/actions/terraform-setup' with ref 'main', not a pinned commit hash

Check warning on line 333 in .github/workflows/infra_apply.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_apply.yaml' step
Uses Step
uses 'pagopa/dx/actions/terraform-plan-storage-download' with ref 'main', not a pinned commit hash

Check warning on line 71 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Check warning on line 88 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 84 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan.yaml' step
Uses Step: get-version
uses 'pagopa/dx/.github/actions/get-terraform-version' with ref 'main', not a pinned commit hash

Check warning on line 158 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}

Check warning on line 174 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Check warning on line 227 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan.yaml' step
Uses Step
uses 'pagopa/dx/actions/csp-login' with ref 'main', not a pinned commit hash

Check warning on line 231 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan.yaml' step
Uses Step: set-terraform-version
uses 'pagopa/dx/.github/actions/terraform-setup' with ref 'main', not a pinned commit hash

Check warning on line 280 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan.yaml' step
Uses Step: plan
uses 'pagopa/dx/actions/filter-terraform-plan' with ref 'main', not a pinned commit hash

Check warning on line 337 in .github/workflows/infra_plan.yaml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'infra_plan.yaml' step
Uses Step: comment
uses 'pagopa/dx/actions/pr-comment' with ref 'main', not a pinned commit hash