Skip to content

updated GHA workflows - #4

Merged
niravpanchal11 merged 1 commit into
masterfrom
feature/GHA-patch-dev
Feb 14, 2026
Merged

niravpanchal11 merged 1 commit into
masterfrom
feature/GHA-patch-dev

Conversation

@niravpanchal11

@niravpanchal11 niravpanchal11 commented Feb 14, 2026 •

Copy link
Copy Markdown
Owner

Summary by Sourcery

Update GitHub Actions workflows for CloudFormation deployment and post-merge branch cleanup to use modern patterns and dependencies.

Build:

  • Add a workflow requirements file and install Python dependencies for deployment tooling in the CloudFormation deploy workflow.

CI:

  • Modernize the CloudFormation deployment workflow by replacing deprecated output syntax with GITHUB_OUTPUT, updating action versions, and renaming jobs/steps for consistency.
  • Adjust the deployment packaging and S3 upload steps to rely on AWS SAM packaging and simplify which assets are synced to S3.
  • Update the auto-delete merged branch workflow to use the latest checkout action version.

@niravpanchal11
niravpanchal11 merged commit 4dc9c64 into master Feb 14, 2026
1 of 3 checks passed
@sourcery-ai

sourcery-ai Bot commented Feb 14, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

This PR modernizes and hardens the GitHub Actions workflows for CloudFormation deployment and automatic branch deletion by updating deprecated syntax, aligning action versions, adding Python dependency management, and cleaning up minor naming and parameter issues.

Sequence diagram for updated GitHub Actions CloudFormation deployment

sequenceDiagram
  actor Dev
  participant GitHub as GitHub_Repo
  participant WF as GHA_Workflow_cft_deploy
  participant JobEnv as Job_ENV
  participant JobDep as Job_DeployCloudFormation
  participant AWSIAM as AWS_IAM_Role
  participant AWSS3 as AWS_S3_Bucket
  participant AWSCF as AWS_CloudFormation

  Dev->>GitHub: Push commit to deployment branch
  GitHub->>WF: Trigger cft-deploy workflow on push

  WF->>JobEnv: Start job ENV
  JobEnv->>JobEnv: Get UTC date output via GITHUB_OUTPUT
  JobEnv->>JobEnv: Determine environment_name based on branch
  JobEnv-->>WF: Output environment_name

  WF->>JobDep: Start job DeployCloudFormation with environment outputs
  JobDep->>JobDep: Checkout code using actions/checkout v6
  JobDep->>JobDep: Run cfn-lint GitHub Action and lint template.yml
  JobDep->>JobDep: Setup Python 3.13 and install pip dependencies
  JobDep->>JobDep: Set BRANCH env and file permissions
  JobDep->>AWSIAM: Resolve deployment role per environment
  AWSIAM-->>JobDep: Deployment role ARN
  JobDep->>AWSIAM: Assume role via AWS credentials action
  AWSIAM-->>JobDep: Temporary AWS credentials

  JobDep->>JobDep: Setup AWS SAM CLI
  JobDep->>JobDep: Run sam build using container
  JobDep->>AWSS3: sam package uploads build artifacts and template
  AWSS3-->>JobDep: Packaged template URL

  JobDep->>AWSS3: Sync lambda directory and upload template.yml
  JobDep->>AWSCF: Deploy stack with packaged template and parameters
  AWSCF-->>JobDep: Stack update or create result
  JobDep-->>WF: Job success
  WF-->>GitHub: Report workflow status
  GitHub-->>Dev: Show deployment result in checks
Loading

Flow diagram for updated CloudFormation deployment job steps

flowchart TD
  A[Push to target branch] --> B[Job ENV Get Date]
  B --> C[Job ENV Determine environment_name]
  C --> D[Job DeployCloudFormation starts]
  D --> E[Checkout repository with actions/checkout@v6]
  E --> F[Run cfn-lint GitHub Action]
  F --> G[Print cfn-lint version and lint template.yml]
  G --> H[Setup Python 3.13 with actions/setup-python@v6]
  H --> I[Install pip dependencies from requirements.txt]
  I --> J[Set BRANCH environment variable]
  J --> K[Set read permissions on tags dev qa prod json]
  K --> L[Set DEPLOYMENT_ENV role arn and S3 bucket based on branch]
  L --> M[Configure AWS credentials via assumed role]
  M --> N[Setup AWS SAM]
  N --> O[Run sam build using container]
  O --> P[Run sam package to upload build artifacts and template.yml]
  P --> Q[Upload lambda code and template.yml directly to S3]
  Q --> R[Deploy or update CloudFormation stack with parameter overrides]
  R --> S[Workflow completes]
Loading

File-Level Changes

Change Details Files
Update CloudFormation deployment workflow to use current GitHub Actions patterns and correct naming.
  • Rename workflow and deploy job to use consistent 'CloudFormation' casing.
  • Replace deprecated ::set-output syntax with the recommended $GITHUB_OUTPUT pattern for step outputs.
  • Standardize step names and minor formatting for readability.
.github/workflows/cft-deploy.yml
Refresh actions and tooling versions and add explicit Python dependency management for the deployment pipeline.
  • Upgrade actions/checkout to v6 and ScottBrenner/cfn-lint-action to v2 in the deploy workflow.
  • Introduce a Python 3.13 setup step using actions/setup-python@v6 with pip caching.
  • Install runtime tools via a new requirements.txt (requests, boto3) within the workflow.
.github/workflows/cft-deploy.yml
.github/workflows/requirements.txt
Tighten and clean up the AWS SAM build/package and S3 upload steps.
  • Rename SAM steps for clarity and ensure sam package is invoked in a dedicated step.
  • Remove unused S3 sync operations for config/ and glue/ and keep only the Lambda and template uploads.
  • Normalize CloudFormation capabilities list formatting by adding consistent spacing after commas.
.github/workflows/cft-deploy.yml
Align the auto-delete merged branch workflow with the latest checkout action.
  • Bump actions/checkout from v4 to v6 in the auto-delete-merged-branch workflow.
  • Tidy whitespace for consistency in that workflow.
.github/workflows/auto-delete-merged-branch.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@github-actions
github-actions Bot deleted the feature/GHA-patch-dev branch February 14, 2026 09:15

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 3 issues, and left some high level feedback:

  • The workflow now references actions/checkout@v6 and actions/setup-python@v6, which do not exist yet; consider pinning to the latest stable major versions (e.g. @v4/@v5) and ideally to specific commit SHAs for reliability.
  • You’ve switched the runtime to Python 3.13, which is still very new and may not be fully supported by SAM or some dependencies; consider staying on 3.12 unless you have a specific need and have verified compatibility.
  • The previous aws s3 sync of config/ and glue/ directories was removed from the deployment workflow; if those assets are still needed by your stacks, you may want to retain or replace that sync step to avoid changing deployment behavior unintentionally.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- The workflow now references `actions/checkout@v6` and `actions/setup-python@v6`, which do not exist yet; consider pinning to the latest stable major versions (e.g. `@v4`/`@v5`) and ideally to specific commit SHAs for reliability.
- You’ve switched the runtime to Python 3.13, which is still very new and may not be fully supported by SAM or some dependencies; consider staying on 3.12 unless you have a specific need and have verified compatibility.
- The previous `aws s3 sync` of `config/` and `glue/` directories was removed from the deployment workflow; if those assets are still needed by your stacks, you may want to retain or replace that sync step to avoid changing deployment behavior unintentionally.

## Individual Comments

### Comment 1
<location> `.github/workflows/cft-deploy.yml:52-53` </location>
<code_context>
       contents: read
     steps:
     - name: Checkout
-      uses: actions/checkout@v2
-    
+      uses: actions/checkout@v6
+
     - name: cfn-lint-action
</code_context>

<issue_to_address>
**issue (bug_risk):** Using `actions/checkout@v6` is likely invalid and will break the workflow.

`actions/checkout` only has published versions up to `v4`. Using `@v6` will fail at runtime with `Action not found`. Please update this to a valid version (e.g. `@v4`).
</issue_to_address>

### Comment 2
<location> `.github/workflows/auto-delete-merged-branch.yml:15-16` </location>
<code_context>
     runs-on: ubuntu-latest
     steps:
       - name: Checkout code
-        uses: actions/checkout@v4
-        
+        uses: actions/checkout@v6
+
       - name: Run if Pull Request is merged/closed
</code_context>

<issue_to_address>
**issue (bug_risk):** The auto-delete workflow also references a non-existent `actions/checkout@v6`.

This version of `actions/checkout` doesn’t exist and will cause the workflow to fail. Please switch to a valid version (e.g., `actions/checkout@v4`).
</issue_to_address>

### Comment 3
<location> `.github/workflows/cft-deploy.yml:126-129` </location>
<code_context>
     - name: Run AWS SAM Build
       run: sam build --use-container --template-file template.yml
-      
-    - name: sam package
-      run: sam package --template-file .aws-sam/build/template.yaml --s3-bucket ${{env.S3_BUCKET}} --output-template-file template.yml --kms-key-id alias/aws/s3

-    - name: Upload CloudFormation Template to S3
+    - name: Run AWS SAM Package
       run: |
</code_context>

<issue_to_address>
**question (bug_risk):** Config and glue asset uploads to S3 were removed; confirm if those artifacts are no longer required.

If any existing stacks or downstream jobs still read `config/` or `glue/` from this S3 bucket, they’ll fail once those paths stop being uploaded. If these assets are truly deprecated, no change needed; otherwise consider restoring or replacing the previous sync behavior.
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment on lines 52 to +53
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue (bug_risk): Using actions/checkout@v6 is likely invalid and will break the workflow.

actions/checkout only has published versions up to v4. Using @v6 will fail at runtime with Action not found. Please update this to a valid version (e.g. @v4).

Comment on lines 15 to +16
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue (bug_risk): The auto-delete workflow also references a non-existent actions/checkout@v6.

This version of actions/checkout doesn’t exist and will cause the workflow to fail. Please switch to a valid version (e.g., actions/checkout@v4).

Comment on lines -126 to -129
- name: sam package
run: sam package --template-file .aws-sam/build/template.yaml --s3-bucket ${{env.S3_BUCKET}} --output-template-file template.yml --kms-key-id alias/aws/s3

- name: Upload CloudFormation Template to S3

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

question (bug_risk): Config and glue asset uploads to S3 were removed; confirm if those artifacts are no longer required.

If any existing stacks or downstream jobs still read config/ or glue/ from this S3 bucket, they’ll fail once those paths stop being uploaded. If these assets are truly deprecated, no change needed; otherwise consider restoring or replacing the previous sync behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant