Skip to content

feat: added banner and update subscription check to make maintained actions free for public repos - #33

Merged
Raj-StepSecurity merged 1 commit into
mainfrom
feat/update-subscription-check
Apr 27, 2026
Merged

Raj-StepSecurity merged 1 commit into
mainfrom
feat/update-subscription-check

Conversation

@Raj-StepSecurity

Copy link
Copy Markdown
Collaborator

Summary

  • Added StepSecurity Maintained Action banner to README.md
  • Updated subscription validation: public repositories are now free (no API check)
  • Upgraded Node.js runtime to node24 (if applicable)
  • Updated workflow files with configurable node_version input (if applicable)

Changes by type

  • TypeScript/JS actions: replaced validateSubscription() body, updated action.yml to node24, updated 3 workflow files, rebuilt dist/
  • Docker actions: replaced entrypoint.sh subscription block, ensured jq is installed in Dockerfile
  • Composite actions: added Subscription check step to action.yml

Verification

  • Subscription check skips for public repos
  • Subscription check fires for private repos
  • README banner is present at the top
  • Build passes (TS/JS actions)

Auto-generated by StepSecurity update-propagator. Task ID: 20260427T124822Z

@claude

claude Bot commented Apr 27, 2026 •

Copy link
Copy Markdown

Claude finished @Raj-StepSecurity's task —— View job


Comprehensive PR Review

I'll provide comprehensive feedback on this pull request based on the specified review criteria.

Review Summary

  • Determine action type (node/docker/composite)
  • Review general action requirements
  • Check license and copyright
  • Verify action.yml structure
  • Review security and workflow files
  • Validate README banner and usage examples
  • Verify subscription check implementation
  • Check for security vulnerabilities
  • Review type-specific requirements
  • Provide final assessment

Action Type Identified: This is a Node.js-based action (uses node24 runtime with dist/index.js main entry point)

✅ REVIEW RESULTS - PASSED

✅ General Action Requirements - PASSED

  • ✅ action.yml file present with correct author: step-security
  • ✅ SECURITY.md file present
  • ✅ Required workflows present: auto_cherry_pick.yml and actions_release.yml in .github/workflows/
  • ✅ Forbidden files absent: No renovate.json, PULL_REQUEST.md, ISSUE_TEMPLATE/, CHANGELOG.md, .vscode/, FUNDING.yml

✅ License and Copyright - PASSED

  • ✅ Apache-2.0 License present with correct StepSecurity copyright (line 189: Copyright 2025 StepSecurity)

✅ README Requirements - PASSED

  • ✅ StepSecurity banner present at top of README (line 1)
  • ✅ Usage examples use major version only (@v4) - no complete semver tags found
  • ✅ Banner links to correct URL: https://docs.stepsecurity.io/actions/stepsecurity-maintained-actions

✅ Subscription Check Implementation - PASSED

  • ✅ Correct API endpoint: https://agent.api.stepsecurity.io/v1/github/${GITHUB_REPOSITORY}/actions/maintained-actions-subscription (src/main.ts:36)
  • ✅ Upstream variable correctly set: 'jfrog/setup-jfrog-cli' matches auto_cherry_pick.yml original-owner: "jfrog" + repo-name: "setup-jfrog-cli" (src/main.ts:16)
  • ✅ Public repo logic: Returns early for public repos without API call (src/main.ts:29)
  • ✅ Private repo validation: Makes API call only for private repos
  • ✅ Error handling: Proper 403 handling and timeout logic

✅ Security Analysis - PASSED

  • ✅ No dangerous functions found: No eval(), exec() (only legitimate @actions/exec usage), or system() calls
  • ✅ Dependencies: All dependencies are legitimate GitHub Actions packages and well-known libraries
  • ✅ Build artifacts: dist/ folder is properly generated and contains compiled code

✅ Node.js Action Specific Requirements - PASSED

  • ✅ package.json author: Set to step-security (package.json:33)
  • ✅ package.json repository: Contains step-security (package.json:22)
  • ✅ dist folder present: Contains compiled action code
  • ✅ Build script present: npm run build script available (package.json:12)
  • ✅ Dependencies usage: All dependencies are used appropriately
  • ✅ Node.js version: Upgraded to Node 24 runtime (action.yml:45)
  • ✅ Workflow configurations: Both required workflow files have node_version input

🎉 FINAL ASSESSMENT: APPROVED

This pull request successfully implements all required StepSecurity maintained action standards:

Key Changes Validated:

  1. ✅ Banner Addition: StepSecurity maintained action banner correctly placed at top of README
  2. ✅ Subscription Logic: Public repositories are now free (no API check required)
  3. ✅ Node.js Upgrade: Successfully upgraded from older Node version to Node 24
  4. ✅ Workflow Updates: All workflow files properly updated with configurable node_version
  5. ✅ Code Quality: No security vulnerabilities or code quality issues found

Security Assessment:

  • No security vulnerabilities detected
  • Proper input validation and error handling
  • Safe dependency usage
  • Appropriate timeout configurations (3000ms)

The implementation follows all specified guidelines and maintains security best practices. The subscription validation correctly differentiates between public and private repositories, and the upstream reference properly matches the original repository configuration.

Recommendation: ✅ APPROVE AND MERGE

@Raj-StepSecurity
Raj-StepSecurity merged commit 3054b55 into main Apr 27, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants