From c5e7754de8207025102c2b4c9e37ef1428b8ea41 Mon Sep 17 00:00:00 2001 From: Cody Spath Date: Wed, 23 Sep 2026 16:59:03 -0400 Subject: [PATCH] chore: update to ld-find-code-refs 2.18.1 Picks up the Go toolchain pin and dependency bumps released in ld-find-code-refs 2.18.1, which clear the 69 govulncheck findings reported against the 2.17.1 binary (CVE-2025-68121, CVE-2026-39821, CVE-2026-45570, CVE-2026-1229). The scanner image launchdarkly/ld-find-code-refs-github-action:2.18.1 is published on Docker Hub. Verified that the shipped 2.18.1 binary reports go1.26.8 and that a binary-mode govulncheck against the published artifact returns no actionable findings. Synced from ld-find-code-refs build/metadata/github-actions at v2.18.1. Co-Authored-By: Claude Opus 5 --- Dockerfile | 2 +- README.md | 8 ++++---- docker/action.yml | 4 ++-- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/Dockerfile b/Dockerfile index ffc39fd..c50f77b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM launchdarkly/ld-find-code-refs-github-action:2.17.0 +FROM launchdarkly/ld-find-code-refs-github-action:2.18.1 LABEL com.github.actions.name="LaunchDarkly Code References" LABEL com.github.actions.description="Find references to feature flags in your code." diff --git a/README.md b/README.md index 218cd9c..05c0229 100644 --- a/README.md +++ b/README.md @@ -28,7 +28,7 @@ jobs: with: fetch-depth: 11 # This value must be set if the lookback configuration option is not disabled for find-code-references. Read more: https://github.com/launchdarkly/ld-find-code-refs#searching-for-unused-flags-extinctions - name: LaunchDarkly Code References - uses: launchdarkly/find-code-references@v2.17.0 + uses: launchdarkly/find-code-references@v2.18.1 with: accessToken: ${{ secrets.LD_ACCESS_TOKEN }} projKey: LD_PROJECT_KEY @@ -64,11 +64,11 @@ jobs: password: ${{ secrets.REGISTRY_TOKEN }} - name: LaunchDarkly Code References # Pin to a release that includes the docker/ entry point (see changelog). - uses: launchdarkly/find-code-references/docker@v2.17.0 + uses: launchdarkly/find-code-references/docker@v2.18.1 with: accessToken: ${{ secrets.LD_ACCESS_TOKEN }} projKey: LD_PROJECT_KEY - dockerImage: your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.17.0 + dockerImage: your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.18.1 ``` Mirror the public image `launchdarkly/ld-find-code-refs-github-action` into your registry (pin `dockerImage` to the scanner image tag you mirrored; it can lag the Action tag). This entry point requires a Docker CLI on the runner (included on GitHub-hosted `ubuntu-*` runners). Existing workflows that use the root Action do not need to change. @@ -104,7 +104,7 @@ jobs: with: fetch-depth: 11 # This value must be set if the lookback configuration option is not disabled for find-code-references. Read more: https://github.com/launchdarkly/ld-find-code-refs#searching-for-unused-flags-extinctions - name: LaunchDarkly Code References - uses: launchdarkly/find-code-references@v2.17.0 + uses: launchdarkly/find-code-references@v2.18.1 with: accessToken: ${{ secrets.LD_ACCESS_TOKEN }} projKey: LD_PROJECT_KEY diff --git a/docker/action.yml b/docker/action.yml index 419536d..465d2d9 100644 --- a/docker/action.yml +++ b/docker/action.yml @@ -52,12 +52,12 @@ inputs: description: >- Container image to run. Defaults to the public Docker Hub image used by the root Action. Set this to your mirrored/proxy image (for example - your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.17.0). + your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.18.1). Authenticate to private registries with docker/login-action (or equivalent) in a prior step. Requires a runner with a Docker CLI (GitHub-hosted ubuntu-* runners include one). required: false - default: "launchdarkly/ld-find-code-refs-github-action:2.17.0" + default: "launchdarkly/ld-find-code-refs-github-action:2.18.1" runs: using: composite steps: