From 358dbb9e460fd9c9529b55cc8b27e862365711af Mon Sep 17 00:00:00 2001 From: Cody Spath Date: Wed, 30 Sep 2026 10:23:23 -0400 Subject: [PATCH] chore: update to ld-find-code-refs 2.18.3 Picks up 2.18.3, which carries the pelletier/go-toml/v2 v2.4.3 bump (XRAY-1033007) on top of the toolchain pin and dependency work from 2.18.0. Scanner image ld-find-code-refs-github-action:2.18.3 is published on Docker Hub, and the 2.18.3 release binary was verified to report go1.26.8 with go-toml v2.4.3. Also switches the usage examples from an exact Action tag to `@v2`. The 2.18.1 sync rewrote those lines to `@v2.18.1`, but this repo was tagged v2.18.0, so the examples have been pointing at a tag that does not exist and 404 when copy-pasted. Floating on `@v2` fixes them and removes the need to rewrite them each release -- moving the v2 tag is what delivers a new scanner to consumers regardless. The prose in this README already described the root Action as `@v2`. The `dockerImage` input keeps an exact tag; there is no floating `:2` tag on Docker Hub for the scanner image. Synced from ld-find-code-refs build/metadata/github-actions. Co-Authored-By: Claude Opus 5 --- Dockerfile | 2 +- README.md | 9 ++++----- docker/action.yml | 4 ++-- 3 files changed, 7 insertions(+), 8 deletions(-) diff --git a/Dockerfile b/Dockerfile index c50f77b..fb48aa3 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM launchdarkly/ld-find-code-refs-github-action:2.18.1 +FROM launchdarkly/ld-find-code-refs-github-action:2.18.3 LABEL com.github.actions.name="LaunchDarkly Code References" LABEL com.github.actions.description="Find references to feature flags in your code." diff --git a/README.md b/README.md index 05c0229..7e4bc9d 100644 --- a/README.md +++ b/README.md @@ -28,7 +28,7 @@ jobs: with: fetch-depth: 11 # This value must be set if the lookback configuration option is not disabled for find-code-references. Read more: https://github.com/launchdarkly/ld-find-code-refs#searching-for-unused-flags-extinctions - name: LaunchDarkly Code References - uses: launchdarkly/find-code-references@v2.18.1 + uses: launchdarkly/find-code-references@v2 with: accessToken: ${{ secrets.LD_ACCESS_TOKEN }} projKey: LD_PROJECT_KEY @@ -63,12 +63,11 @@ jobs: username: ${{ secrets.REGISTRY_USER }} password: ${{ secrets.REGISTRY_TOKEN }} - name: LaunchDarkly Code References - # Pin to a release that includes the docker/ entry point (see changelog). - uses: launchdarkly/find-code-references/docker@v2.18.1 + uses: launchdarkly/find-code-references/docker@v2 with: accessToken: ${{ secrets.LD_ACCESS_TOKEN }} projKey: LD_PROJECT_KEY - dockerImage: your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.18.1 + dockerImage: your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.18.3 ``` Mirror the public image `launchdarkly/ld-find-code-refs-github-action` into your registry (pin `dockerImage` to the scanner image tag you mirrored; it can lag the Action tag). This entry point requires a Docker CLI on the runner (included on GitHub-hosted `ubuntu-*` runners). Existing workflows that use the root Action do not need to change. @@ -104,7 +103,7 @@ jobs: with: fetch-depth: 11 # This value must be set if the lookback configuration option is not disabled for find-code-references. Read more: https://github.com/launchdarkly/ld-find-code-refs#searching-for-unused-flags-extinctions - name: LaunchDarkly Code References - uses: launchdarkly/find-code-references@v2.18.1 + uses: launchdarkly/find-code-references@v2 with: accessToken: ${{ secrets.LD_ACCESS_TOKEN }} projKey: LD_PROJECT_KEY diff --git a/docker/action.yml b/docker/action.yml index 465d2d9..d2b506e 100644 --- a/docker/action.yml +++ b/docker/action.yml @@ -52,12 +52,12 @@ inputs: description: >- Container image to run. Defaults to the public Docker Hub image used by the root Action. Set this to your mirrored/proxy image (for example - your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.18.1). + your.registry.example/launchdarkly/ld-find-code-refs-github-action:2.18.3). Authenticate to private registries with docker/login-action (or equivalent) in a prior step. Requires a runner with a Docker CLI (GitHub-hosted ubuntu-* runners include one). required: false - default: "launchdarkly/ld-find-code-refs-github-action:2.18.1" + default: "launchdarkly/ld-find-code-refs-github-action:2.18.3" runs: using: composite steps: