Skip to content

Commit fa82a45

Browse files
Upgrade: [dependabot] - bump NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml from 5.5.0 to 5.6.3 (#2060)
Bumps [NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml](https://github.com/nhsdigital/eps-common-workflows) from 5.5.0 to 5.6.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nhsdigital/eps-common-workflows/releases">NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml's releases</a>.</em></p> <blockquote> <h2>v5.6.3</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.6.2...v5.6.3">5.6.3</a> (2026-03-06)</h2> <h3>Chore</h3> <ul> <li>[AEA-5986] - Allow semantic release to handle python build (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/83">#83</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/141907b215220e95e3ed3811d0fe8fa18675dbed">141907b</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/22773044980">Release workflow run</a> - Workflow ID: 22773044980</p> <p>It was initialized by <a href="https://github.com/originalphil">originalphil</a></p> <h2>v5.6.2</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.6.1...v5.6.2">5.6.2</a> (2026-03-05)</h2> <h3>Upgrade</h3> <ul> <li>[dependabot] - bump conventional-changelog-eslint from 6.0.0 to 6.1.0 (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/82">#82</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/91d5906640395bcda81360fb4b78adaf2f09fd2e">91d5906</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/22730971742">Release workflow run</a> - Workflow ID: 22730971742</p> <p>It was initialized by <a href="https://github.com/apps/eps-autoapprove-dependabot">eps-autoapprove-dependabot[bot]</a></p> <h2>v5.6.1</h2> <h2><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.6.0...v5.6.1">5.6.1</a> (2026-03-05)</h2> <h3>Fix</h3> <ul> <li>[AEA-0000] - Always run valid trivy scans even if a previous scan failed, so that all vulnerabilities are identified at once. Shorten feedback cycle for vulnerabilities across multiple scans. (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/78">#78</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/d116ba935f2a9544c7bcc6dc37ea997fada6e780">d116ba9</a>)</li> </ul> <h2>Info</h2> <p><a href="https://github.com/NHSDigital/eps-common-workflows/actions/runs/22727356777">Release workflow run</a> - Workflow ID: 22727356777</p> <p>It was initialized by <a href="https://github.com/connoravo-nhs">connoravo-nhs</a></p> <h2>v5.6.0</h2> <h1><a href="https://github.com/NHSDigital/eps-common-workflows/compare/v5.5.3...v5.6.0">5.6.0</a> (2026-03-05)</h1> <h3>Fix</h3> <ul> <li>[AEA-5986] - Fix publish fame library (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/77">#77</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/aac5b797ee198b8bd260d618cf7cbdf723860033">aac5b79</a>)</li> </ul> <h3>New</h3> <ul> <li>[AEA-5986] - Publish to PyPI (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/76">#76</a>) (<a href="https://github.com/NHSDigital/eps-common-workflows/commit/de2118390681f2e1701dddcaa463dcea743a6e92">de21183</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/141907b215220e95e3ed3811d0fe8fa18675dbed"><code>141907b</code></a> Chore: [AEA-5986] - Allow semantic release to handle python build (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/83">#83</a>)</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/91d5906640395bcda81360fb4b78adaf2f09fd2e"><code>91d5906</code></a> Upgrade: [dependabot] - bump conventional-changelog-eslint from 6.0.0 to 6.1....</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/d116ba935f2a9544c7bcc6dc37ea997fada6e780"><code>d116ba9</code></a> Fix: [AEA-0000] - Always run valid trivy scans even if a previous scan failed...</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/aac5b797ee198b8bd260d618cf7cbdf723860033"><code>aac5b79</code></a> Fix: [AEA-5986] - Fix publish fame library (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/77">#77</a>)</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/d5222938de3b91e0fe94db73d61eb9e0f781b1ed"><code>d522293</code></a> Upgrade: [dependabot] - bump aquasecurity/trivy-action from 0.34.0 to 0.34.1 ...</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/de2118390681f2e1701dddcaa463dcea743a6e92"><code>de21183</code></a> New: [AEA-5986] - Publish to PyPI (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/76">#76</a>)</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/8404cf6e3a61ac8de4d1644e175e288aa4965815"><code>8404cf6</code></a> Chore: [AEA-0000] - Removes unused inputs and updates readme (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/74">#74</a>)</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/2a083514efbae0b9ddacfcc87b9d285767b686b8"><code>2a08351</code></a> Chore: [AEA-0000] - Combines get_config_values and verify_attestation into a ...</li> <li><a href="https://github.com/NHSDigital/eps-common-workflows/commit/d215f841eb18b803e339e4ed597ed1f30e086e17"><code>d215f84</code></a> Fix: [AEA-0000] - add back in .tool-versions (<a href="https://redirect.github.com/nhsdigital/eps-common-workflows/issues/72">#72</a>)</li> <li>See full diff in <a href="https://github.com/nhsdigital/eps-common-workflows/compare/36677e1d6bfaa010d7b78942a1ade12fbefecb80...141907b215220e95e3ed3811d0fe8fa18675dbed">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml&package-manager=github_actions&previous-version=5.5.0&new-version=5.6.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Anthony Brown <anthony.brown8@nhs.net>
1 parent 6c31e50 commit fa82a45

10 files changed

Lines changed: 61 additions & 198 deletions

.github/workflows/cdk_diff_code.yml

Lines changed: 2 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -31,27 +31,18 @@ on:
3131
required: false
3232
type: string
3333
default: eu-west-2
34-
runtime_docker_image:
34+
pinned_image:
3535
type: string
3636
required: true
37-
verify_published_from_main_image:
38-
type: boolean
39-
required: true
4037
secrets:
4138
CLOUD_FORMATION_DIFF_ROLE:
4239
required: true
4340

4441
jobs:
45-
verify_attestation:
46-
uses: NHSDigital/eps-common-workflows/.github/workflows/verify-attestation.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
47-
with:
48-
runtime_docker_image: "${{ inputs.runtime_docker_image }}"
49-
verify_published_from_main_image: ${{ inputs.verify_published_from_main_image }}
5042
deploy_cdk_code:
5143
runs-on: ubuntu-22.04
52-
needs: verify_attestation
5344
container:
54-
image: ${{ needs.verify_attestation.outputs.pinned_image }}
45+
image: ${{ inputs.pinned_image }}
5546
options: --user 1001:1001 --group-add 128
5647
defaults:
5748
run:

.github/workflows/cdk_package_code.yml

Lines changed: 2 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,24 +3,15 @@ name: cdk package code
33
on:
44
workflow_call:
55
inputs:
6-
runtime_docker_image:
6+
pinned_image:
77
type: string
88
required: true
9-
verify_published_from_main_image:
10-
type: boolean
11-
required: true
129

1310
jobs:
14-
verify_attestation:
15-
uses: NHSDigital/eps-common-workflows/.github/workflows/verify-attestation.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
16-
with:
17-
runtime_docker_image: "${{ inputs.runtime_docker_image }}"
18-
verify_published_from_main_image: ${{ inputs.verify_published_from_main_image }}
1911
package_cdk_code:
2012
runs-on: ubuntu-22.04
21-
needs: verify_attestation
2213
container:
23-
image: ${{ needs.verify_attestation.outputs.pinned_image }}
14+
image: ${{ inputs.pinned_image }}
2415
options: --user 1001:1001 --group-add 128
2516
defaults:
2617
run:

.github/workflows/cdk_release_code.yml

Lines changed: 2 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -28,27 +28,18 @@ on:
2828
required: false
2929
type: string
3030
default: eu-west-2
31-
runtime_docker_image:
31+
pinned_image:
3232
type: string
3333
required: true
34-
verify_published_from_main_image:
35-
type: boolean
36-
required: true
3734
secrets:
3835
CLOUD_FORMATION_DEPLOY_ROLE:
3936
required: true
4037

4138
jobs:
42-
verify_attestation:
43-
uses: NHSDigital/eps-common-workflows/.github/workflows/verify-attestation.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
44-
with:
45-
runtime_docker_image: "${{ inputs.runtime_docker_image }}"
46-
verify_published_from_main_image: ${{ inputs.verify_published_from_main_image }}
4739
deploy_cdk_code:
4840
runs-on: ubuntu-22.04
49-
needs: verify_attestation
5041
container:
51-
image: ${{ needs.verify_attestation.outputs.pinned_image }}
42+
image: ${{ inputs.pinned_image }}
5243
options: --user 1001:1001 --group-add 128
5344
defaults:
5445
run:

.github/workflows/ci.yml

Lines changed: 11 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -9,48 +9,29 @@ env:
99

1010
jobs:
1111
get_config_values:
12-
runs-on: ubuntu-22.04
13-
outputs:
14-
tag_format: ${{ steps.load-config.outputs.TAG_FORMAT }}
15-
devcontainer_version: ${{ steps.load-config.outputs.DEVCONTAINER_VERSION }}
16-
devcontainer_image: ${{ steps.load-config.outputs.DEVCONTAINER_IMAGE }}
17-
steps:
18-
- name: Checkout code
19-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
20-
21-
- name: Load config value
22-
id: load-config
23-
run: |
24-
TAG_FORMAT=$(yq '.TAG_FORMAT' .github/config/settings.yml)
25-
DEVCONTAINER_IMAGE=$(jq -r '.build.args.IMAGE_NAME' .devcontainer/devcontainer.json)
26-
DEVCONTAINER_VERSION=$(jq -r '.build.args.IMAGE_VERSION' .devcontainer/devcontainer.json)
27-
{
28-
echo "TAG_FORMAT=$TAG_FORMAT"
29-
echo "DEVCONTAINER_IMAGE=$DEVCONTAINER_IMAGE"
30-
echo "DEVCONTAINER_VERSION=$DEVCONTAINER_VERSION"
31-
} >> "$GITHUB_OUTPUT"
12+
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@8404cf6e3a61ac8de4d1644e175e288aa4965815
13+
with:
14+
verify_published_from_main_image: true
3215

3316
quality_checks:
34-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
17+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@141907b215220e95e3ed3811d0fe8fa18675dbed
3518
needs: [get_config_values]
3619
with:
37-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
20+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
3821
secrets:
3922
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
4023

4124
package_code:
4225
uses: ./.github/workflows/sam_package_code.yml
4326
needs: get_config_values
4427
with:
45-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
46-
verify_published_from_main_image: true
28+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
4729

4830
package_cdk_code:
4931
uses: ./.github/workflows/cdk_package_code.yml
5032
needs: get_config_values
5133
with:
52-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
53-
verify_published_from_main_image: true
34+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
5435

5536
get_commit_id:
5637
runs-on: ubuntu-22.04
@@ -67,10 +48,9 @@ jobs:
6748
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@aac5b797ee198b8bd260d618cf7cbdf723860033
6849
with:
6950
dry_run: true
70-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
51+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
7152
branch_name: main
7253
tag_format: ${{ needs.get_config_values.outputs.tag_format }}
73-
verify_published_from_main_image: true
7454
secrets: inherit
7555

7656
deploy_dev_stacks:
@@ -89,8 +69,7 @@ jobs:
8969
deploy_artillery: true
9070
deploy_drift_detection: true
9171
is_pull_request: false
92-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
93-
verify_published_from_main_image: true
72+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
9473
secrets:
9574
cf_create_changeset_role: ${{ secrets.DEV_CLOUD_FORMATION_CREATE_CHANGESET_ROLE }}
9675
cf_deploy_role: ${{ secrets.DEV_CLOUD_FORMATION_DEPLOY_ROLE }}
@@ -134,8 +113,7 @@ jobs:
134113
deploy_artillery: false
135114
deploy_drift_detection: true
136115
is_pull_request: false
137-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
138-
verify_published_from_main_image: true
116+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
139117
secrets:
140118
cf_create_changeset_role: ${{ secrets.QA_CLOUD_FORMATION_CREATE_CHANGESET_ROLE }}
141119
cf_deploy_role: ${{ secrets.QA_CLOUD_FORMATION_DEPLOY_ROLE }}
@@ -164,8 +142,7 @@ jobs:
164142
deploy_artillery: true
165143
deploy_drift_detection: true
166144
is_pull_request: false
167-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
168-
verify_published_from_main_image: true
145+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
169146
secrets:
170147
cf_create_changeset_role: ${{ secrets.REF_CLOUD_FORMATION_CREATE_CHANGESET_ROLE }}
171148
cf_deploy_role: ${{ secrets.REF_CLOUD_FORMATION_DEPLOY_ROLE }}

.github/workflows/cloudformation.yml

Lines changed: 4 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -31,12 +31,9 @@ on:
3131
required: false
3232
type: string
3333
default: "{}"
34-
runtime_docker_image:
34+
pinned_image:
3535
type: string
3636
required: true
37-
verify_published_from_main_image:
38-
type: boolean
39-
required: true
4037
secrets:
4138
cf_deploy_role:
4239
required: false
@@ -46,17 +43,11 @@ on:
4643
required: true
4744

4845
jobs:
49-
verify_attestation:
50-
uses: NHSDigital/eps-common-workflows/.github/workflows/verify-attestation.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
51-
with:
52-
runtime_docker_image: "${{ inputs.runtime_docker_image }}"
53-
verify_published_from_main_image: ${{ inputs.verify_published_from_main_image }}
5446
create_change_set:
55-
needs: verify_attestation
5647
name: Create ${{ inputs.stack_name }} change set
5748
runs-on: ubuntu-22.04
5849
container:
59-
image: ${{ needs.verify_attestation.outputs.pinned_image }}
50+
image: ${{ inputs.pinned_image }}
6051
options: --user 1001:1001 --group-add 128
6152
defaults:
6253
run:
@@ -189,10 +180,10 @@ jobs:
189180
execute_change_set:
190181
name: Execute ${{ inputs.stack_name }} change Set
191182
if: ${{ inputs.execute_change_set == true }}
192-
needs: [create_change_set, verify_attestation]
183+
needs: [create_change_set]
193184
runs-on: ubuntu-22.04
194185
container:
195-
image: ${{ needs.verify_attestation.outputs.pinned_image }}
186+
image: ${{ inputs.pinned_image }}
196187
options: --user 1001:1001 --group-add 128
197188
defaults:
198189
run:

.github/workflows/pull_request.yml

Lines changed: 10 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -15,32 +15,15 @@ jobs:
1515
AUTOMERGE_APP_ID: ${{ secrets.AUTOMERGE_APP_ID }}
1616
AUTOMERGE_PEM: ${{ secrets.AUTOMERGE_PEM }}
1717
get_config_values:
18-
runs-on: ubuntu-22.04
19-
outputs:
20-
tag_format: ${{ steps.load-config.outputs.TAG_FORMAT }}
21-
devcontainer_version: ${{ steps.load-config.outputs.DEVCONTAINER_VERSION }}
22-
devcontainer_image: ${{ steps.load-config.outputs.DEVCONTAINER_IMAGE }}
23-
steps:
24-
- name: Checkout code
25-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
26-
27-
- name: Load config value
28-
id: load-config
29-
run: |
30-
TAG_FORMAT=$(yq '.TAG_FORMAT' .github/config/settings.yml)
31-
DEVCONTAINER_IMAGE=$(jq -r '.build.args.IMAGE_NAME' .devcontainer/devcontainer.json)
32-
DEVCONTAINER_VERSION=$(jq -r '.build.args.IMAGE_VERSION' .devcontainer/devcontainer.json)
33-
{
34-
echo "TAG_FORMAT=$TAG_FORMAT"
35-
echo "DEVCONTAINER_IMAGE=$DEVCONTAINER_IMAGE"
36-
echo "DEVCONTAINER_VERSION=$DEVCONTAINER_VERSION"
37-
} >> "$GITHUB_OUTPUT"
18+
uses: NHSDigital/eps-common-workflows/.github/workflows/get-repo-config.yml@8404cf6e3a61ac8de4d1644e175e288aa4965815
19+
with:
20+
verify_published_from_main_image: false
3821

3922
quality_checks:
40-
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
23+
uses: NHSDigital/eps-common-workflows/.github/workflows/quality-checks-devcontainer.yml@141907b215220e95e3ed3811d0fe8fa18675dbed
4124
needs: [get_config_values]
4225
with:
43-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
26+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
4427
secrets:
4528
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
4629

@@ -51,15 +34,13 @@ jobs:
5134
uses: ./.github/workflows/sam_package_code.yml
5235
needs: get_config_values
5336
with:
54-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
55-
verify_published_from_main_image: false
37+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
5638

5739
package_cdk_code:
5840
uses: ./.github/workflows/cdk_package_code.yml
5941
needs: get_config_values
6042
with:
61-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
62-
verify_published_from_main_image: false
43+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
6344

6445
get_issue_number:
6546
runs-on: ubuntu-22.04
@@ -89,13 +70,12 @@ jobs:
8970

9071
tag_release:
9172
needs: [get_config_values]
92-
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@36677e1d6bfaa010d7b78942a1ade12fbefecb80
73+
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@141907b215220e95e3ed3811d0fe8fa18675dbed
9374
with:
9475
dry_run: true
95-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
76+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
9677
branch_name: ${{ github.event.pull_request.head.ref }}
9778
tag_format: ${{ needs.get_config_values.outputs.TAG_FORMAT }}
98-
verify_published_from_main_image: false
9979
secrets: inherit
10080
get_commit_id:
10181
runs-on: ubuntu-22.04
@@ -123,8 +103,7 @@ jobs:
123103
deploy_artillery: true
124104
deploy_drift_detection: false
125105
is_pull_request: true
126-
runtime_docker_image: "${{ needs.get_config_values.outputs.devcontainer_image }}:githubactions-${{ needs.get_config_values.outputs.devcontainer_version }}"
127-
verify_published_from_main_image: false
106+
pinned_image: ${{ needs.get_config_values.outputs.pinned_image }}
128107
secrets:
129108
cf_create_changeset_role: ${{ secrets.DEV_CLOUD_FORMATION_DEPLOY_ROLE }}
130109
cf_deploy_role: ${{ secrets.DEV_CLOUD_FORMATION_DEPLOY_ROLE }}

0 commit comments

Comments
 (0)