Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 19 additions & 4 deletions github/resource_github_actions_organization_permissions.go
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,11 @@ func resourceGithubActionsOrganizationPermissions() *schema.Resource {
},
},
},
"sha_pinning_required": {
Type: schema.TypeBool,
Optional: true,
Description: "Whether pinning to a specific SHA is required for all actions and reusable workflows in an organization.",
},
},
}
}
Expand Down Expand Up @@ -147,12 +152,18 @@ func resourceGithubActionsOrganizationPermissionsCreateOrUpdate(d *schema.Resour
allowedActions := d.Get("allowed_actions").(string)
enabledRepositories := d.Get("enabled_repositories").(string)

actionsPermissions := github.ActionsPermissions{
AllowedActions: &allowedActions,
EnabledRepositories: &enabledRepositories,
}

if v, ok := d.GetOk("sha_pinning_required"); ok {
actionsPermissions.SHAPinningRequired = github.Ptr(v.(bool))
}

_, _, err = client.Actions.UpdateActionsPermissions(ctx,
orgName,
github.ActionsPermissions{
AllowedActions: &allowedActions,
EnabledRepositories: &enabledRepositories,
})
actionsPermissions)
if err != nil {
return err
}
Expand Down Expand Up @@ -280,6 +291,10 @@ func resourceGithubActionsOrganizationPermissionsRead(d *schema.ResourceData, me
return err
}

if err = d.Set("sha_pinning_required", actionsPermissions.GetSHAPinningRequired()); err != nil {
return err
}

return nil
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@
enabledRepositories := "selected"
githubOwnedAllowed := true
verifiedAllowed := true
shaPinningRequired := true

Check failure on line 49 in github/resource_github_actions_organization_permissions_test.go

View workflow job for this annotation

GitHub Actions / Continuous Integration

declared and not used: shaPinningRequired
randomID := acctest.RandStringFromCharSet(5, acctest.CharSetAlphaNum)
repoName := fmt.Sprintf("%srepo-act-org-perm-%s", testResourcePrefix, randomID)

Expand All @@ -63,6 +64,7 @@
github_owned_allowed = %t
patterns_allowed = ["actions/cache@*", "actions/checkout@*"]
verified_allowed = %t
sha_pinning_required = %t
}
enabled_repositories_config {
repository_ids = [github_repository.test.repo_id]
Expand Down
13 changes: 13 additions & 0 deletions github/resource_github_actions_repository_permissions.go
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,11 @@ func resourceGithubActionsRepositoryPermissions() *schema.Resource {
Description: "The GitHub repository.",
ValidateDiagFunc: toDiagFunc(validation.StringLenBetween(1, 100), "repository"),
},
"sha_pinning_required": {
Type: schema.TypeBool,
Optional: true,
Description: "Whether pinning to a specific SHA is required for all actions and reusable workflows in a repository.",
},
},
}
}
Expand Down Expand Up @@ -125,6 +130,10 @@ func resourceGithubActionsRepositoryPermissionsCreateOrUpdate(d *schema.Resource
repoActionPermissions.AllowedActions = &allowedActions
}

if v, ok := d.GetOk("sha_pinning_required"); ok {
repoActionPermissions.SHAPinningRequired = github.Ptr(v.(bool))
}

_, _, err := client.Repositories.UpdateActionsPermissions(ctx,
owner,
repoName,
Expand Down Expand Up @@ -210,6 +219,10 @@ func resourceGithubActionsRepositoryPermissionsRead(d *schema.ResourceData, meta
return err
}

if err = d.Set("sha_pinning_required", actionsPermissions.GetSHAPinningRequired()); err != nil {
return err
}

return nil
}

Expand Down
2 changes: 2 additions & 0 deletions github/resource_github_actions_repository_permissions_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@
allowedActions := "selected"
githubOwnedAllowed := true
verifiedAllowed := true
shaPinningRequired := true

Check failure on line 52 in github/resource_github_actions_repository_permissions_test.go

View workflow job for this annotation

GitHub Actions / Continuous Integration

declared and not used: shaPinningRequired (typecheck)
randomID := acctest.RandStringFromCharSet(5, acctest.CharSetAlphaNum)
repoName := fmt.Sprintf("%srepo-act-perms-%s", testResourcePrefix, randomID)

Expand All @@ -65,6 +66,7 @@
github_owned_allowed = %t
patterns_allowed = ["actions/cache@*", "actions/checkout@*"]
verified_allowed = %t
sha_pinning_required = %t
}
repository = github_repository.test.name
}
Expand Down
Loading