Skip to content

Commit 703ff17

Browse files
chore: synced local '.github/workflows/export_github_data.yml' with remote 'tools/sre_file_sync/export_github_data.yml'
1 parent 859767c commit 703ff17

File tree

1 file changed

+16
-1
lines changed

1 file changed

+16
-1
lines changed

.github/workflows/export_github_data.yml

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,13 @@ on:
44
schedule:
55
- cron: "20 7 * * *"
66

7+
permissions:
8+
id-token: write
9+
contents: read
10+
issues: read
11+
pull-requests: read
12+
security-events: read
13+
714
jobs:
815
export-data:
916
runs-on: ubuntu-latest
@@ -15,11 +22,19 @@ jobs:
1522
DNS_PROXY_LOGANALYTICSWORKSPACEID: ${{ secrets.LOG_ANALYTICS_WORKSPACE_ID }}
1623
DNS_PROXY_LOGANALYTICSSHAREDKEY: ${{ secrets.LOG_ANALYTICS_WORKSPACE_KEY }}
1724
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
25+
- name: Configure AWS credentials using OIDC
26+
uses: aws-actions/configure-aws-credentials@7474bc4690e29a8392af63c5b98e7449536d5c3a # v4.3.1
27+
with:
28+
role-to-assume: arn:aws:iam::739275439843:role/data-lake-github-data-export
29+
role-session-name: GithubDataExport
30+
aws-region: ca-central-1
1831
- name: Export Data
19-
uses: cds-snc/github-repository-metadata-exporter@7f8f3eccaf3e15675fc70611e913ec1458510540
32+
uses: cds-snc/github-repository-metadata-exporter@ccde2e2cc2d351bbc6fcd4146d2193d8da2b7a95
2033
with:
2134
github-app-id: ${{ secrets.SRE_BOT_RO_APP_ID }}
2235
github-app-installation-id: ${{ secrets.SRE_BOT_RO_INSTALLATION_ID }}
2336
github-app-private-key: ${{ secrets.SRE_BOT_RO_PRIVATE_KEY }}
2437
log-analytics-workspace-id: ${{ secrets.LOG_ANALYTICS_WORKSPACE_ID }}
2538
log-analytics-workspace-key: ${{ secrets.LOG_ANALYTICS_WORKSPACE_KEY }}
39+
s3-bucket: ${{ secrets.DATA_LAKE_GITHUB_METADATA_EXPORT_S3_BUCKET }}
40+
aws-region: ${{ secrets.DATA_LAKE_GITHUB_METADATA_EXPORT_AWS_REGION }}

0 commit comments

Comments
 (0)