Skip to content

feat: added banner and update subscription check to make maintained actions free for public repos - #30

Closed
anurag-stepsecurity wants to merge 1 commit into
mainfrom
feat/update-subscription-check
Closed

anurag-stepsecurity wants to merge 1 commit into
mainfrom
feat/update-subscription-check

Conversation

@anurag-stepsecurity

Copy link
Copy Markdown
Contributor

Summary

  • Added StepSecurity Maintained Action banner to README.md
  • Updated subscription validation: public repositories are now free (no API check)
  • Upgraded Node.js runtime to node24
  • Updated workflow files with configurable node_version input

Changes by type

  • TypeScript/JS actions: replaced validateSubscription() body, updated action.yml to node24, updated 3 workflow files, rebuilt dist/

Verification

  • Subscription check skips for public repos
  • Subscription check fires for private repos
  • README banner is present at the top
  • Build passes

Auto-generated by StepSecurity update-propagator. Task ID: 20260423T092801Z

…ctions free for public repos

Signed-off-by: Anurag Rajawat <anurag@stepsecurity.io>
@claude

claude Bot commented Apr 23, 2026 •

Copy link
Copy Markdown

Claude finished @anurag-stepsecurity's task —— View job


PR Review: StepSecurity Maintained Action Updates

Review Complete ✅

This PR successfully implements the StepSecurity maintained action standards with excellent compliance.

✅ ALL REQUIREMENTS PASSING

📋 General Requirements

  • ✅ License: Apache 2.0 with StepSecurity copyright (2025)
  • ✅ Action.yml: Correct author "step-security", Node.js 24 runtime
  • ✅ SECURITY.md: Present with proper reporting email
  • ✅ Required workflows: auto_cherry_pick.yml ✅, actions_release.yml ✅
  • ✅ Prohibited files: All absent (FUNDING.yml, renovate.json, PULL_REQUEST.md, ISSUE_TEMPLATE/, CHANGELOG.md, .vscode/)
  • ✅ README banner: StepSecurity maintained action banner at top
  • ✅ Usage examples: Correct major version format (@v4)

🔒 Subscription Check Implementation - EXCELLENT

  • ✅ Correct API endpoint: https://agent.api.stepsecurity.io/v1/github/${GITHUB_REPOSITORY}/actions/maintained-actions-subscription
  • ✅ Perfect upstream value: jfrog/setup-jfrog-cli (matches auto_cherry_pick.yml configuration)
  • ✅ NEW: Public repo optimization: Skips API call for public repositories (repoPrivate === false)
  • ✅ Robust error handling: 403 status → subscription error, timeouts gracefully handled
  • ✅ User experience: Clear console messaging with color formatting

⚙️ Node.js Specific Requirements

  • ✅ Package.json: Author "step-security", repository field contains "step-security"
  • ✅ Dependencies: All used appropriately (verified imports vs package.json)
  • ✅ Dist folder: Present with compiled bundles
  • ✅ Build workflow: Configurable node_version input in audit_package.yml ✅

🛡️ Security Analysis

  • ✅ No security vulnerabilities detected
  • ✅ Safe use of process.env, Buffer.from(), and exec() calls
  • ✅ Input validation and proper error handling throughout
  • ✅ No dangerous patterns (eval, new Function, etc.)

🎯 Key Improvements in This PR

  1. Public repository support: Major UX improvement - public repos now free without API calls
  2. Node.js 24 upgrade: Modern runtime with security improvements
  3. StepSecurity banner: Proper branding and documentation links
  4. Enhanced user messaging: Clear subscription status indicators

📊 Final Assessment: APPROVED ✅

This action exemplifies StepSecurity maintained action standards. The subscription check implementation is particularly well-designed with the new public repository optimization. All security, compliance, and functional requirements are met.

Recommendation: ✅ Ready to merge

@Raj-StepSecurity
Raj-StepSecurity deleted the feat/update-subscription-check branch April 27, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants