From d16de43ba6d7d081effd751a422eb7fb6fc2f0f3 Mon Sep 17 00:00:00 2001 From: Mike Merkulov Date: Thu, 8 Oct 2026 14:33:01 +0300 Subject: [PATCH 1/3] fixed warnings in test --- .../IntegrationTests.cs | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/Tests/VaultSharp.Extensions.Configuration.Test/IntegrationTests.cs b/Tests/VaultSharp.Extensions.Configuration.Test/IntegrationTests.cs index ba70ba2..1bf3a79 100644 --- a/Tests/VaultSharp.Extensions.Configuration.Test/IntegrationTests.cs +++ b/Tests/VaultSharp.Extensions.Configuration.Test/IntegrationTests.cs @@ -971,8 +971,8 @@ public async Task Success_TokenNoAuthMethod() var container = this.PrepareVaultContainer(tokenId: ""); try { - await container.StartAsync(cts.Token).ConfigureAwait(false); - await this.LoadDataAsync("http://localhost:8200", values).ConfigureAwait(false); + await container.StartAsync(cts.Token); + await this.LoadDataAsync("http://localhost:8200", values); // Moq mock of PostProcessHttpClientHandlerAction implementation: var mockConfigureProxyAction = new Mock>(); @@ -998,7 +998,7 @@ public async Task Success_TokenNoAuthMethod() finally { cts.Cancel(); - await container.DisposeAsync().ConfigureAwait(false); + await container.DisposeAsync(); } } From 9b30d120f711f70c2710e36ed283b4b71ebca609 Mon Sep 17 00:00:00 2001 From: Mike Merkulov Date: Thu, 8 Oct 2026 14:33:23 +0300 Subject: [PATCH 2/3] Updated github actions --- .github/workflows/build.yml | 10 +++++----- .github/workflows/master.yml | 6 +++--- .github/workflows/release-drafter.yml | 2 +- .github/workflows/release.yml | 8 ++++---- 4 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 4068960..1f2b46a 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -17,7 +17,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: lfs: true fetch-depth: 0 @@ -25,7 +25,7 @@ jobs: run: git fetch --tags shell: bash - name: 'Install .NET Core SDK' - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@v6 with: dotnet-version: | 6.0.x @@ -45,12 +45,12 @@ jobs: if: github.event_name == 'pull_request' run: cp coverage/*/coverage.cobertura.xml coverage/coverage.cobertura.xml - name: 'Publish Code Coverage' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: Coverage Cobertura Report path: './coverage/coverage.cobertura.xml' - name: 'Publish Test Results' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: Tests HTML Report path: './coverage/VaultSharp.Extensions.Configuration.Test.html' @@ -67,7 +67,7 @@ jobs: indicators: true output: both - name: Add Coverage PR Comment - uses: marocchino/sticky-pull-request-comment@v2 + uses: marocchino/sticky-pull-request-comment@v3 if: github.event_name == 'pull_request' with: recreate: true diff --git a/.github/workflows/master.yml b/.github/workflows/master.yml index 3dfeb41..2d62783 100644 --- a/.github/workflows/master.yml +++ b/.github/workflows/master.yml @@ -19,12 +19,12 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: lfs: true fetch-depth: 0 - name: 'Install .NET Core SDK' - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@v6 with: dotnet-version: | 6.0.x @@ -50,7 +50,7 @@ jobs: echo "COVERAGE=$COVERAGE%" >> $GITHUB_ENV echo "BRANCH=${GITHUB_HEAD_REF:-${GITHUB_REF#refs/heads/}}" >> $GITHUB_ENV - name: Create the Badgegg - uses: schneegans/dynamic-badges-action@v1.7.0 + uses: schneegans/dynamic-badges-action@v1.9.0 with: auth: ${{ secrets.GIST_SECRET }} gistID: 5242a4e2d58a428062b3a59824d5864e diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index 99fe14d..e94f084 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -9,6 +9,6 @@ jobs: update_release_draft: runs-on: ubuntu-latest steps: - - uses: release-drafter/release-drafter@v6 + - uses: release-drafter/release-drafter@v7 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4d459b1..dd6829e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -11,7 +11,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: lfs: true fetch-depth: 0 @@ -19,7 +19,7 @@ jobs: run: git fetch --tags shell: pwsh - name: 'Install .NET Core SDK' - uses: actions/setup-dotnet@v4 + uses: actions/setup-dotnet@v6 with: dotnet-version: | 6.0.x @@ -35,12 +35,12 @@ jobs: NUGET_API_KEY: ${{ secrets.NUGET_API_KEY }} shell: pwsh - name: 'Publish Code Coverage' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: tests path: './Artefacts/**/coverage.opencover.xml' - name: 'Publish Test Results' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: tests path: './Artefacts/VaultSharp.Extensions.Configuration.Test.html' From 8a4948aff6519255b2d6a5229f18b7d3f115a678 Mon Sep 17 00:00:00 2001 From: Mike Merkulov Date: Thu, 8 Oct 2026 14:34:26 +0300 Subject: [PATCH 3/3] Added explicit least-privilege permissions to all four workflows --- .github/workflows/build.yml | 4 ++++ .github/workflows/master.yml | 3 +++ .github/workflows/release-drafter.yml | 4 ++++ .github/workflows/release.yml | 3 +++ 4 files changed, 14 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 1f2b46a..a2d1646 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -3,6 +3,10 @@ name: Build on: pull_request: +permissions: + contents: read + pull-requests: write + env: # Set the DOTNET_SKIP_FIRST_TIME_EXPERIENCE environment variable to stop wasting time caching packages DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true diff --git a/.github/workflows/master.yml b/.github/workflows/master.yml index 2d62783..6eab856 100644 --- a/.github/workflows/master.yml +++ b/.github/workflows/master.yml @@ -5,6 +5,9 @@ on: branches: - master +permissions: + contents: read + env: # Set the DOTNET_SKIP_FIRST_TIME_EXPERIENCE environment variable to stop wasting time caching packages DOTNET_SKIP_FIRST_TIME_EXPERIENCE: true diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index e94f084..31f6383 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -5,6 +5,10 @@ on: branches: - master +permissions: + contents: write + pull-requests: read + jobs: update_release_draft: runs-on: ubuntu-latest diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index dd6829e..e969b4c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,6 +5,9 @@ on: tags: - '*' +permissions: + contents: read + jobs: build: name: Release