Skip to content

fix(actions): remove outdated actions and update documentation accordingly - #8110

Merged
cx-artur-ribeiro merged 6 commits into
masterfrom
remove-outdated-actions
Sep 7, 2026
Merged

cx-artur-ribeiro merged 6 commits into
masterfrom
remove-outdated-actions

Conversation

@cx-artur-ribeiro

@cx-artur-ribeiro cx-artur-ribeiro commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Reason for Proposed Changes

  • Since the last Pull Request updating the CI, some actions were left untouched since they were not used. We are currently deprecating unused actions, as well as update any documentation that references those actions.

Proposed Changes

  • Remove outdated actions:
    • release-docker-github-action.yaml: Updates docs/docker with new released version. Not used since 2022 and not updated as well. To remove this action, we need to remove the associated code related to this action (docs/docker);
    • update_software_versions.yaml: updates software versions for the new release on .github/scripts/update_versions/requirements.txt;
    • update-install-script.yaml: not used since 2021, only updates the install.sh script which is not used at the moment. The script in question does not exist as well, this action should have been deleted a long time ago with the deletion of the script;
    • release-nightly: we haven't used or released nightly versions in 2,5+ years, so we don't need this action at all;
    • realease.yaml: unused action, full commented, will be removed as well.
  • Remove all KICS_BOT_PAT variable usage;
  • Update python registry to echohq;
  • Fix security vulnerabilities.

I submit this contribution under the Apache-2.0 license.

@cx-artur-ribeiro cx-artur-ribeiro self-assigned this Sep 7, 2026
@stepsecurity-app

stepsecurity-app Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 47
  • secrets.KICS_BOT_PAT at line 102
  • secrets.GITHUB_TOKEN at line 103

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-artur-ribeiro) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@cx-artur-ribeiro
cx-artur-ribeiro marked this pull request as ready for review September 7, 2026 13:36
@cx-artur-ribeiro
cx-artur-ribeiro merged commit 785f788 into master Sep 7, 2026
32 of 39 checks passed
@cx-artur-ribeiro
cx-artur-ribeiro deleted the remove-outdated-actions branch September 7, 2026 16:12
cx-andre-pereira pushed a commit that referenced this pull request Sep 8, 2026
…ingly (#8110)

* update: remove outdated and unused actions, use echohq for python install instead of local installation step.

* remove: outdated actions and update packages to fix vulnerabilities

* remove: unused actions, update set-output deprecated parameter to use github action output

* fix: lint
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
kics 2.2.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## What's Changed
* docs(release): update queries catalog, index and dockerfile for upcoming release by @cx-artur-ribeiro in Checkmarx/kics#8094
* fix(query): added missing case to "Last User is Root" Dockerfile query. by @cx-andre-pereira in Checkmarx/kics#8095
* feat(queries): new queries to check if synapse workspace managed virtual network is enabled by @cx-ricardo-jesus in Checkmarx/kics#8097
* refactor(descriptions): remove pkg/descriptions and related CLI flag by @cx-ricardo-jesus in Checkmarx/kics#8092
* CISO-1264 - Update GitHub Actions runner labels by @cx-jonathan-hartman in Checkmarx/kics#8093
* fix(query): Fix for Missing Backslash Support on Copy_With_More_Than_Two_Arguments_Not_Ending_With_Slash query by @cx-andre-pereira in Checkmarx/kics#8099
* fix(actions): refactor gh actions to fix CI by @cx-artur-ribeiro in Checkmarx/kics#8098
* fix(query): change to keyExpectedValue on ARM 'default_azure_storage_account_network_access_is_too_permissive' query by @cx-andre-pereira in Checkmarx/kics#8101
* update(version): rename VERSION build-arg to ENGINE_VERSION by @cx-artur-ribeiro in Checkmarx/kics#8102
* fix(query): correct keyExpectedValue and keyActualValue in redshift_not_encrypted by @cx-ricardo-jesus in Checkmarx/kics#8105
* fix(analyzer): bound file analysis workers by @omribz156 in Checkmarx/kics#8058
* fix(actions): remove outdated actions and update documentation accordingly by @cx-artur-ribeiro in Checkmarx/kics#8110
* fix(action): remove concurrent group from run projects github action by @cx-artur-ribeiro in Checkmarx/kics#8111
* fix(test): normalize timestamp comparison in TestInitCycloneDxReport by @cx-artur-ribeiro in Checkmarx/kics#8113
* fix(actions): fix security vulnerabilities and update ci with new enforced rules by @cx-artur-ribeiro in Checkmarx/kics#8118
* fix(release): gate kics release workflows behind release environment by @cx-lior-poterman in Checkmarx/kics#8108
* fix(validator): update queries validator for cwe and risk score fields by @cx-artur-ribeiro in Checkmarx/kics#8028
* fix(version): new available version with additional v prefix by @cx-artur-ribeiro in Checkmarx/kics#8119
* fix(analyzer): improvement to dockerfile scanning by @cx-andre-pereira in Checkmarx/kics#8114
* chore(release): removed unused goreleaser configuration files by @cx-ricardo-jesus in Checkmarx/kics#8122
* fix(filesystem): skip cache files by extension by @cx-laura-rodrigues in Checkmarx/kics#8112
* fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands by @cx-andre-pereira in Checkmarx/kics#8115
* docs(release): update queries catalog, index and dockerfile for 2.2.0 by @cx-artur-ribeiro in Checkmarx/kics#8126

## New Contributors
* @cx-jonathan-hartman made their first contribution in Checkmarx/kics#8093
* @omribz156 made their first contribution in Checkmarx/kics#8058
* @cx-lior-poterman made their first contribution in Checkmarx/kics#8108

**Full Changelog**: https://github.com/Checkmarx/kics/compare/v2.1.21...v2.2.0</pre>
  <p>View the full release notes at <a href="https://github.com/Checkmarx/kics/releases/tag/v2.2.0">https://github.com/Checkmarx/kics/releases/tag/v2.2.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!20473
cx-andre-pereira pushed a commit that referenced this pull request Sep 29, 2026
…ingly (#8110)

* update: remove outdated and unused actions, use echohq for python install instead of local installation step.

* remove: outdated actions and update packages to fix vulnerabilities

* remove: unused actions, update set-output deprecated parameter to use github action output

* fix: lint
cx-andre-pereira pushed a commit that referenced this pull request Sep 29, 2026
…ingly (#8110)

* update: remove outdated and unused actions, use echohq for python install instead of local installation step.

* remove: outdated actions and update packages to fix vulnerabilities

* remove: unused actions, update set-output deprecated parameter to use github action output

* fix: lint
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants