Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Bump configure-aws-credentials to v6 and dflook/terraform-* to v3 in the Terraform workflows

Abierto Apto para principiantes
#170 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
76/100
Tipo de issue
Refactorización
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
github-actions, terraform

Línea de trabajo

Empieza leyendo .github/workflows/terraform-plan.yaml y .github/workflows/terraform-apply.yaml, y localiza las líneas uses: relevantes en lugar de basarte en los números de línea. Comprueba el filtro de rutas y coordínate con el trabajo relacionado de OIDC y checkout antes de editar. Se considera terminado cuando solo cambian los pins de las actions especificadas, un cambio no-op en un archivo .tf produce un plan vacío y el apply posterior al merge se completa correctamente sin una anotación de depreciación de Node.js 20.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

complexity: medium feature: maintenance role: DevOps Engineer size: 2pt
Overview

We need to bump aws-actions/configure-aws-credentials from @v4 to @v6 and dflook/terraform-plan/dflook/terraform-apply from @v1 to @v3 in both Terraform workflows, because configure-aws-credentials@v4 runs on the deprecated Node 20 and the dflook pins are four releases behind, including a fix for terraform-apply wrongly aborting on a plan that contains both imports and warnings.

Action Items

aws-actions/configure-aws-credentials — @v4 to @v6, 2 lines:

  • .github/workflows/terraform-plan.yaml:25 and .github/workflows/terraform-apply.yaml:25.
  • Go to v6, not v4-for-parity and not v5. Reading action.yml at each tag: v3 = node16, v4 = node20, v5 = node20, v6 = node24. Only v6 clears the Node 20 deprecation. This repo was previously described as the "good" state that incubator's @v3 should be brought up to — that was wrong, @v4 here is deprecated too.
  • Note this is the opposite call from actions/checkout in hackforla/devops#183, which deliberately stops at v5 rather than going current. The two look inconsistent and are not: for checkout an intermediate version already reaches Node 24, and for this action nothing below v6 does.

dflook/terraform-plan and dflook/terraform-apply — @v1 to @v3, 2 lines:

  • terraform-plan.yaml:32 (dflook/terraform-plan@v1) and terraform-apply.yaml:32 (dflook/terraform-apply@v1).
  • @v1 is a floating tag, so this is less stale than it looks — it resolves to v1.49.0 (2025-05-29), not the 2021 release. Latest is v3.0.0 (2026-07-18). The honest framing is four missed releases, not "two majors behind".
  • The Node 20 deprecation does not apply to these two. Both are Docker actions (runs: using: docker), so no JS runtime is involved. That is why going straight to current is fine here.
  • Checked before this ticket was written, so you do not have to: the only input removed across both majors is the deprecated var: input (v2.0.0), and neither workflow uses it — they pass only path, backend_config_file and auto_approve, all still present at v3.0.0. The real risk is the debian 11 → 12 → 13 base-image bump.

Out of scope — do not change these here:

  • actions/checkout@v4 at line 23 of both files belongs to hackforla/devops#183. Leave it alone. If hackforla/devops#183's devops-security PR has already merged, rebase; if it has not, whoever merges second rebases. Same two files, adjacent lines.

Verification — read this before opening the PR, it is the awkward part:

  • Both workflows filter on paths: ['**/*.tf'] only, so a PR that changes only .github/workflows/*.yaml triggers neither plan nor apply and shows no checks at all. That is expected, not a failure — and it means this change is not self-testing the way the equivalent incubator work (hackforla/incubator#158, hackforla/incubator#159) was.
  • To exercise the plan job in the same PR, include a no-op change to a .tf file (a comment line). Treat an empty plan as a hard gate: if the plan shows any resource change, stop and raise it rather than merging.
  • After the PR merges, terraform-apply.yaml runs a real terraform apply against AWS on push to main. Confirm that run succeeds and carries no "Node.js 20 is deprecated" annotation. This cannot be checked from the branch.
Resources/Instructions
  • Files (default branch is main): .github/workflows/terraform-plan.yaml, .github/workflows/terraform-apply.yaml
  • Line numbers accurate 2026-08-27 and will drift — locate each pin by its uses: line rather than by position.
  • Coordination with the OIDC work. There is an unticketed plan to move both workflows off static AWS credentials onto OIDC role assumption, which rewrites configure-aws-credentials — the very line this ticket bumps. If that work starts before this is picked up, fold this in and close this issue as covered rather than editing the same lines twice.
  • Related: hackforla/devops#183 (actions/checkout in the same files), hackforla/incubator#158 (same configure-aws-credentials bump, already ticketed), hackforla/incubator#159 (same dflook bump, already ticketed).
Lenguaje dominante
HCL
Estrellas
1
Forks
14
Merge medio
16 min
PR fusionados (30 d)
13

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de hackforla/devops-security

Todos los issues de hackforla/devops-security

Issues similares

Más issues de DevOps

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.