Repository navigation
Conversation
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
fa15b26 to
e845b43
Compare
0ab2ada to
c4d98e0
Compare
e845b43 to
71121c1
Compare
ffec5ab to
3c2fda3
Compare
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
nick-y-snyk
left a comment
There was a problem hiding this comment.
The code looks right. The script keeps mode 100755, SCRIPT_DIR/../update-site/... still resolves from .circleci/, and all three path references are updated. Merge stays gated on a real stable release, as the description says.
One gap in the runbook. Steps 7 to 9 don't delete the AWS_S3_BUCKET_NAME GitHub secret. After this PR nothing reads it (readme-sync.yml only uses GITHUB_TOKEN), so it should go with the others.
Nits:
- Blocker 1 waits on circleci-infra#66, but #468 says the
snyk-eclipse-plugin-github-releasecontext already exists. #66 only brings it under Terraform, so it doesn't gate this merge. - The re-check commands exclude
:!.local/, but the repo has no.local/directory. It looks like it came from a local setup and can be dropped.
71121c1 to
df083ed
Compare
3c2fda3 to
6da9d96
Compare
Deletes the GitHub Actions release-legacy.yml workflow that was kept as a manual fallback while the CircleCI stable-release pipeline was unproven. Its function is fully replaced by the CircleCI publish-stable job (added in the prior stacked PR) — no on-repo GitHub Actions path to S3 publishing remains. Moves the shared .github/upload-to-s3.sh script to .circleci/, since nothing under .github/ uses it anymore now that the legacy workflow is gone — leaving it at .github/ would be a maintenance trap. The script's path computation is directory-relative and works identically from the new location; only the three .circleci/config.yml references (in build-sign's persist_to_workspace, publish-preview, and publish-stable) change to match. Deletes the 'release-legacy.yml is a fallback until milestone 4' migration note from RELEASE.md — this PR is that milestone. Does NOT deactivate or delete the corresponding IAM access key, the IAM user, or the AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY GitHub repo secrets — those are live-infrastructure actions on real AWS/GitHub credentials and are documented as a manual runbook in the PR description, to be executed by the user after this PR merges. The PR is labelled do-not-merge until at least one real stable release has been cut through the new CircleCI pipeline, per the ticket's 'verify before deactivate, deactivate before delete' ordering. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
df083ed to
496d452
Compare
4ae5adf to
33bfa0a
Compare
Added.
Forgot to update the description, done now.
My local AI being silly, removed. |
nick-y-snyk
left a comment
There was a problem hiding this comment.
Code looks good. Merge stays gated on a real stable release through CircleCI, as the label says.

Final milestone (4 of 4) of IDE-2483 — migrating S3 publishing off static AWS
keys onto CircleCI OIDC. Stacked on #468.
What this PR does (safe to merge from a code-review standpoint)
.github/workflows/release-legacy.yml— the GitHub Actions fallbackkept while the CircleCI
stable-releasepipeline was unproven. Its functionis fully replaced by the CircleCI
publish-stablejob (added in ci: add publish-stable job with CircleCI OIDC, rename release.yml to legacy fallback [IDE-2483] #468)..github/upload-to-s3.shto.circleci/upload-to-s3.sh— nothingunder
.github/uses it anymore once the legacy workflow is gone..circleci/config.ymlreferences to the script's new path(
build-sign'spersist_to_workspace,publish-preview,publish-stable).note from
RELEASE.md— this PR is that migration.circleci config validatepasses.Why this is
do-not-mergeMerging now would delete the still-actively-used GitHub Actions fallback
before its CircleCI replacement is proven end-to-end. Per the ticket's own
"verify before deactivate, deactivate before delete" ordering, this PR stays
gated until:
Blocker before merge:
CircleCI
stable-releasepipeline (tag, GitHub release with asset, ands3://snyk-assets/eclipse/stable/all confirmed).(
circleci-infraPR #66 formalizes the already-existingsnyk-eclipse-plugin-github-releaseCircleCI context in Terraform — itdoesn't gate this merge, since the context already works per #468.)
The diff is reviewable now regardless — opening it ready-for-review means
merge is one click the moment the gate lifts, matching #468's own convention.
Post-merge decommissioning runbook (execute in order — do NOT skip steps; each gates the next)
Prerequisite (already gates this PR's merge): at least one real stable
release has been cut successfully through the new CircleCI
stable-releasepipeline.
release-legacy.yml, moves the S3 uploadscript into
.circleci/).198361731867→ IAM → Users → find the userthat owns the access key currently populating the GitHub secret
AWS_ACCESS_KEY_ID. Note the user's name and the access key's ID. Verifythe key hasn't already been deactivated by someone else.
(Security credentials tab → Access keys → three-dot menu → Deactivate).
Do NOT delete yet — deactivation is reversible; deletion is not.
comes first. During that window, cut at least one real stable release
through CircleCI. Confirm it succeeds end-to-end: tag appears, GitHub
release appears with the ZIP asset,
s3://snyk-assets/eclipse/stable/has the fresh artifact. This is the "publishing confirmed still
working" AC step.
- Rollback if step 4 fails: re-activate the access key (reverse of
step 3). Investigate why the CircleCI OIDC path failed. Do not
proceed to step 5 until step 4 has been re-run and passed.
policies. If it exists solely to hold this access key for this repo's
publishing, delete the IAM user too. If it also holds other policies
or roles used elsewhere, leave the user in place — flag it in the
ticket comment at step 11.
AWS_ACCESS_KEY_ID.AWS_SECRET_ACCESS_KEY.AWS_S3_BUCKET_NAME. Nothing reads it after this PR merges —readme-sync.yml(the only other workflow left) only usesGITHUB_TOKEN.KEYSTORE,KEYSTORE_SHA,KEYSTORE_PASS. These are only read byrelease-legacy.yml, which no longer exists after this PR merges.CircleCI's
build-signuses same-named variables but sources them fromthe
snyk-eclipse-plugin-signingCircleCI context, not from GitHubsecrets.
executed and when (dates + IAM key ID + IAM user name if deleted).
Transition IDE-2483 to Done. Notify
#ideSlack channel that thedecommissioning is complete.
Re-check (after step 11) — run in a fresh clone of
mainEvery command must return zero hits / not exist.
PR stack — merge order
flowchart LR main(["main"]) PR1["#460 build-sign\nCircleCI signing"] PR2["#462 publish-preview\nCircleCI OIDC publish"] PR3["#463 stable-release scaffold\nworkflow + build-sign-stable"] PR4["#468 publish-stable\nOIDC publish"] PR5["remove-legacy-release-workflow ← YOU ARE HERE\nDO NOT MERGE"] main --> PR1 --> PR2 --> PR3 --> PR4 --> PR5 style PR5 fill:#ffd700,color:#000Depends on: #468
Test plan
circleci config validatepassesgit grepsweep forrelease-legacy.yml,AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY, old.github/upload-to-s3.shpath — zero hitsrepo-wide
100755)verifiable by this PR alone)
🤖 Generated with Claude Code