Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions .github/workflows/build-containers.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ env:

jobs:
discover-configs:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
outputs:
Expand Down Expand Up @@ -190,7 +190,7 @@ jobs:
# and built from this commit, so it can never be stale.
build-dockhand:
needs: discover-configs
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: ${{ needs.discover-configs.outputs.changed-configs != '[]' }}
permissions:
contents: read
Expand Down Expand Up @@ -218,7 +218,7 @@ jobs:

verify-provenance:
needs: [discover-configs, build-dockhand]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
# Verify package provenance when we have configs to build
if: ${{ needs.discover-configs.outputs.changed-configs != '[]' }}
strategy:
Expand Down Expand Up @@ -291,7 +291,7 @@ jobs:

mcp-security-scan:
needs: [discover-configs, verify-provenance]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
timeout-minutes: 10
# Only scan configs whose spec.yaml files actually changed
# (not all configs when only go.mod/dockhand changed, since scans don't use dockhand)
Expand Down Expand Up @@ -439,7 +439,7 @@ jobs:
override-check:
needs: [discover-configs]
if: ${{ github.event_name == 'pull_request' && needs.discover-configs.outputs.scan-configs != '[]' }}
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
steps:
Expand Down Expand Up @@ -477,7 +477,7 @@ jobs:

build-containers:
needs: [discover-configs, build-dockhand, verify-provenance, mcp-security-scan]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
timeout-minutes: 60
# `!cancelled()` disables the implicit success() gate on `needs` so this
# job still runs when mcp-security-scan was skipped (e.g. a toolhive bump
Expand Down Expand Up @@ -859,7 +859,7 @@ jobs:
# Save PR number as artifact for the mcp-scan-report workflow.
# This is needed because workflow_run doesn't reliably provide PR info for fork PRs.
save-pr-number:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions: {}
if: github.event_name == 'pull_request'
steps:
Expand All @@ -877,7 +877,7 @@ jobs:

summary:
needs: [discover-configs, verify-provenance, mcp-security-scan, build-containers]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions: {}
if: always()
steps:
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/build-skills.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ env:

jobs:
discover-skill-configs:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
outputs:
Expand Down Expand Up @@ -132,7 +132,7 @@ jobs:

validate-skills:
needs: discover-skill-configs
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: ${{ needs.discover-skill-configs.outputs.changed-configs != '[]' }}
strategy:
matrix:
Expand Down Expand Up @@ -167,7 +167,7 @@ jobs:
resolve-pr-scan:
needs: discover-skill-configs
if: github.event_name == 'push' && github.ref == 'refs/heads/main' && needs.discover-skill-configs.outputs.scan-configs != '[]'
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
actions: read
contents: read
Expand Down Expand Up @@ -301,7 +301,7 @@ jobs:

skill-security-scan:
needs: [discover-skill-configs, resolve-pr-scan]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
timeout-minutes: 35
if: ${{ always() && github.ref == 'refs/heads/main' && needs.discover-skill-configs.outputs.scan-configs != '[]' && needs.resolve-pr-scan.result == 'success' }}
strategy:
Expand Down Expand Up @@ -629,7 +629,7 @@ jobs:

build-skill-artifacts:
needs: [discover-skill-configs, validate-skills, skill-security-scan]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
timeout-minutes: 30
# Aggregate scan result is intentionally not gated here. A failure in one
# skill's scan must not block publishing the rest. The per-cell
Expand Down Expand Up @@ -999,7 +999,7 @@ jobs:

summary:
needs: [discover-skill-configs, validate-skills, skill-security-scan, build-skill-artifacts]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: always()
permissions:
contents: read
Expand Down
9 changes: 5 additions & 4 deletions .github/workflows/check-skills.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ concurrency:

jobs:
discover-skill-configs:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
outputs:
Expand Down Expand Up @@ -80,7 +80,7 @@ jobs:

validate-skills:
needs: discover-skill-configs
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: needs.discover-skill-configs.outputs.changed-configs != '[]'
strategy:
matrix:
Expand Down Expand Up @@ -108,7 +108,7 @@ jobs:

build-skill-artifacts:
needs: [discover-skill-configs, validate-skills]
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: needs.validate-skills.result == 'success'
strategy:
matrix:
Expand Down Expand Up @@ -137,7 +137,7 @@ jobs:

scanner-smoke:
needs: discover-skill-configs
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: needs.discover-skill-configs.outputs.scanner-smoke == 'true'
permissions:
contents: read
Expand Down Expand Up @@ -171,6 +171,7 @@ jobs:
go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.7 \
-ignore 'unexpected key "queue"' \
-ignore 'shellcheck reported issue' \
-ignore 'label "ubuntu-26\.04" is unknown' \
.github/workflows/build-skills.yml \
.github/workflows/check-skills.yml \
.github/workflows/trusted-skill-scan.yml \
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:

lint:
name: Lint
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -38,7 +38,7 @@ jobs:

build:
name: Build
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/mcp-scan-report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ permissions: {}

jobs:
mcp-scan-report:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: github.event.workflow_run.event == 'pull_request'
steps:
- name: Generate GitHub App token
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/periodic-security-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ env:

jobs:
discover-published-images:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
outputs:
Expand All @@ -36,7 +36,7 @@ jobs:

scan-images:
needs: discover-published-images
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: ${{ needs.discover-published-images.outputs.configs != '[]' }}
strategy:
matrix:
Expand Down Expand Up @@ -286,7 +286,7 @@ jobs:

summary:
needs: scan-images
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions: {}
if: always()
steps:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/renovate-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ concurrency:
jobs:
validate-config:
name: Validate Renovate Configuration
runs-on: ubuntu-latest
runs-on: ubuntu-26.04

steps:
- name: Checkout repository
Expand Down Expand Up @@ -70,7 +70,7 @@ jobs:

test-dry-run:
name: Test Renovate Dry Run
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: github.event_name == 'pull_request'

steps:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/skill-scan-report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ permissions: {}

jobs:
skill-scan-report:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
if: github.event.workflow_run.event == 'pull_request_target'
steps:
- name: Generate GitHub App token
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/skill-version-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ concurrency:
jobs:
skill-version-check:
name: Check skill spec.version
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
steps:
- name: Generate GitHub App token
id: app-token
Expand Down Expand Up @@ -69,7 +69,7 @@ jobs:
# makes the bot author of the auto-fix commit identifiable.
skill-version-autofix:
name: Auto-fix skill spec.version (Renovate only)
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
# Only apply the auto-fix for the Renovate bot.
if: >
github.event.pull_request.user.login == 'renovate[bot]' ||
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/trusted-skill-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ permissions: {}

jobs:
discover:
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
pull-requests: read
Expand Down Expand Up @@ -91,7 +91,7 @@ jobs:
name: Trusted skill scan coordination
needs: discover
if: needs.discover.outputs.scan-configs != '[]'
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
timeout-minutes: 80
permissions:
actions: read
Expand Down Expand Up @@ -142,7 +142,7 @@ jobs:
scan:
needs: [discover, wait-for-prior-scan]
if: needs.discover.outputs.scan-configs != '[]'
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
timeout-minutes: 35
strategy:
fail-fast: false
Expand Down Expand Up @@ -631,7 +631,7 @@ jobs:
approve:
needs: [discover, scan]
if: needs.discover.outputs.scan-configs != '[]' && needs.scan.result == 'success'
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions: {}
steps:
- name: Record successful run identity
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ permissions: {}
jobs:
zizmor:
name: zizmor
runs-on: ubuntu-latest
runs-on: ubuntu-26.04
permissions:
contents: read
steps:
Expand Down
Loading