Skip to content

Conversation

@asjohnston-asf
Copy link
Member

@asjohnston-asf asjohnston-asf commented Nov 13, 2025

@cmarshak any concerns with releasing Thursday morning? This will make the new transformer_v0_32 and transformer_v1_32 options available in hyp3-tibet-jpl and hyp3-nisar-jpl.


Verification job https://hyp3-test-api.asf.alaska.edu/jobs/4892b87a-4634-4fdd-b66b-b5251df67faf ran with no issues.

TODO

  • disable hyp3-edc-prod cluster and let desired vcpus drop below 1,200 before merging so the deployment will succeed

cmarshak and others added 18 commits October 27, 2025 15:35
Bumps the pip-deps group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.40.55` | `1.40.64` |
| [asf-search](https://github.com/asfadmin/Discovery-asf_search) | `10.1.1` | `10.1.2` |
| [moto[dynamodb]](https://github.com/getmoto/moto) | `5.1.15` | `5.1.16` |
| [ruff](https://github.com/astral-sh/ruff) | `0.14.1` | `0.14.3` |
| [cfn-lint](https://github.com/aws-cloudformation/cfn-lint) | `1.40.2` | `1.40.3` |



Updates `boto3` from 1.40.55 to 1.40.64
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.40.55...1.40.64)

Updates `asf-search` from 10.1.1 to 10.1.2
- [Release notes](https://github.com/asfadmin/Discovery-asf_search/releases)
- [Changelog](https://github.com/asfadmin/Discovery-asf_search/blob/master/CHANGELOG.md)
- [Commits](asfadmin/Discovery-asf_search@v10.1.1...v10.1.2)

Updates `moto[dynamodb]` from 5.1.15 to 5.1.16
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](getmoto/moto@5.1.15...5.1.16)

Updates `ruff` from 0.14.1 to 0.14.3
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.14.1...0.14.3)

Updates `cfn-lint` from 1.40.2 to 1.40.3
- [Release notes](https://github.com/aws-cloudformation/cfn-lint/releases)
- [Changelog](https://github.com/aws-cloudformation/cfn-lint/blob/main/CHANGELOG.md)
- [Commits](aws-cloudformation/cfn-lint@v1.40.2...v1.40.3)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.40.64
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
- dependency-name: asf-search
  dependency-version: 10.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
- dependency-name: moto[dynamodb]
  dependency-version: 5.1.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
- dependency-name: ruff
  dependency-version: 0.14.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
- dependency-name: cfn-lint
  dependency-version: 1.40.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
move lavas deploy workflow into custom hyp3 deployment workflows
drop unused services sandbox deploy workflow
Bump the pip-deps group across 1 directory with 5 updates
Bumps the pip-deps group with 4 updates: [boto3](https://github.com/boto/boto3), [pytest](https://github.com/pytest-dev/pytest), [ruff](https://github.com/astral-sh/ruff) and [cfn-lint](https://github.com/aws-cloudformation/cfn-lint).


Updates `boto3` from 1.40.64 to 1.40.69
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.40.64...1.40.69)

Updates `pytest` from 8.4.2 to 9.0.0
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@8.4.2...9.0.0)

Updates `ruff` from 0.14.3 to 0.14.4
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.14.3...0.14.4)

Updates `cfn-lint` from 1.40.3 to 1.40.4
- [Release notes](https://github.com/aws-cloudformation/cfn-lint/releases)
- [Changelog](https://github.com/aws-cloudformation/cfn-lint/blob/main/CHANGELOG.md)
- [Commits](aws-cloudformation/cfn-lint@v1.40.3...v1.40.4)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.40.69
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
- dependency-name: pytest
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-deps
- dependency-name: ruff
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
- dependency-name: cfn-lint
  dependency-version: 1.40.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the github-actions-deps group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [ASFHyP3/actions/.github/workflows/reusable-changelog-check.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-create-jira-issue.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-labeled-pr-check.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-release-checklist-comment.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-release.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-ruff.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-mypy.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-secrets-analysis.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |
| [ASFHyP3/actions/.github/workflows/reusable-bump-version.yml](https://github.com/asfhyp3/actions) | `0.20.0` | `0.21.0` |


Updates `ASFHyP3/actions/.github/workflows/reusable-changelog-check.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-create-jira-issue.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-labeled-pr-check.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-release-checklist-comment.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-release.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-ruff.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-mypy.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-secrets-analysis.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

Updates `ASFHyP3/actions/.github/workflows/reusable-bump-version.yml` from 0.20.0 to 0.21.0
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.20.0...v0.21.0)

---
updated-dependencies:
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-changelog-check.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-create-jira-issue.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-labeled-pr-check.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-release-checklist-comment.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-release.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-ruff.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-mypy.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-secrets-analysis.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-bump-version.yml
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
Reduce VPCUs for HyP3 test and prod
…b-actions-deps-7f213fd512

Bump the github-actions-deps group with 9 updates
@asjohnston-asf asjohnston-asf added the patch Bump the patch version number of this project label Nov 13, 2025
jobs:
call-changelog-check-workflow:
uses: ASFHyP3/actions/.github/workflows/reusable-changelog-check.yml@v0.20.0
uses: ASFHyP3/actions/.github/workflows/reusable-changelog-check.yml@v0.21.0

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Copilot Autofix

AI 2 months ago

To fix this issue, an explicit permissions block should be added to the workflow. This block can be placed at the workflow root (applying to all jobs, including the called reusable workflow), or inside the specific job definition. Since the code only shows a single job (using a reusable workflow), placing the permissions block at the root is the cleanest approach and matches GitHub documentation and recommendations.

The most restrictive and generally safe starting point is:

permissions:
  contents: read

If the reusable workflow needs more specific permissions (e.g., write access to pull-requests), additional lines can be added, but contents: read is the safest minimal setting for workflows that only need to check code or metadata.

Add the following near the top, below the name (line 1) and before the on: block (line 3).

Suggested changeset 1
.github/workflows/changelog.yml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/changelog.yml b/.github/workflows/changelog.yml
--- a/.github/workflows/changelog.yml
+++ b/.github/workflows/changelog.yml
@@ -1,5 +1,8 @@
 name: Changelog updated?
 
+permissions:
+  contents: read
+
 on:
   pull_request:
     types:
EOF
@@ -1,5 +1,8 @@
name: Changelog updated?

permissions:
contents: read

on:
pull_request:
types:
Copilot is powered by AI and may make mistakes. Always verify output.
jobs:
call-labeled-pr-check-workflow:
uses: ASFHyP3/actions/.github/workflows/reusable-labeled-pr-check.yml@v0.20.0
uses: ASFHyP3/actions/.github/workflows/reusable-labeled-pr-check.yml@v0.21.0

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {}

Copilot Autofix

AI 2 months ago

To fix the problem, we need to add a permissions block to the workflow file .github/workflows/labeled-pr.yml, setting it at either the root (for all jobs) or under the relevant job (for that job only). Since the current workflow consists of a single job that calls a reusable workflow, it is most straightforward and idiomatic to place the permissions block at the workflow root.

As for which permissions to grant: unless the called reusable workflow’s documentation says otherwise, the most restrictive and safest starting point is to set contents: read. If the workflow requires other permissions (such as to comment on issues or manage pull requests, which is common for PR labeling or status check actions), these should be explicitly set. In the absence of precise requirements, a minimal starting block of contents: read is recommended, which can later be expanded as needed.

The change should be made at the top level of the YAML file, ideally after the name and before the on section for clarity.


Suggested changeset 1
.github/workflows/labeled-pr.yml

Autofix patch

Autofix patch
Run the following command in your local git repository to apply this patch
cat << 'EOF' | git apply
diff --git a/.github/workflows/labeled-pr.yml b/.github/workflows/labeled-pr.yml
--- a/.github/workflows/labeled-pr.yml
+++ b/.github/workflows/labeled-pr.yml
@@ -1,4 +1,6 @@
 name: Is PR labeled?
+permissions:
+  contents: read
 
 on:
   pull_request:
EOF
@@ -1,4 +1,6 @@
name: Is PR labeled?
permissions:
contents: read

on:
pull_request:
Copilot is powered by AI and may make mistakes. Always verify output.
@github-actions
Copy link

github-actions bot commented Nov 13, 2025

Developer checklist

  • Indicated the level of changes to this package by affixing one of these labels:
    • major -- Major changes to the API that may break current workflows
    • minor -- Minor changes to the API that do not break current workflows
    • patch -- Patches and bugfixes for the current version that do not break current workflows
    • bumpless -- Changes to documentation, CI/CD pipelines, etc. that don't affect the software's version
  • (If applicable) Updated the dependencies and indicated any downstream changes that are required
  • Added/updated documentation for these changes
  • Added/updated tests for these changes
  • Verified changes in test deployment and summarized results, e.g. in PR description or comments on the related issue(s)
  • If the step function code has changed, have you drained the job queue before merging?
    • For example, if the interface for a Lambda function has changed to expect different input,
      then currently running jobs (which use the old step function definition) will call the new
      function with the old input. So we must drain the job queue before deployment, so that the new
      function is only called by the new step function definition.

Reviewer checklist

  • Have all dependencies been updated?
  • Is the level of changes labeled appropriately?
  • Are all the changes described appropriately in CHANGELOG.md?
  • Has the documentation been adequately updated?
  • Are the tests adequate?
  • Have the changes been verified in the test deployment?

@cmarshak
Copy link
Contributor

cmarshak commented Nov 13, 2025

No concerns with me. Thanks! Super appreciate using this.

@asjohnston-asf asjohnston-asf marked this pull request as ready for review November 13, 2025 17:05
@asjohnston-asf asjohnston-asf requested review from a team as code owners November 13, 2025 17:05
@asjohnston-asf asjohnston-asf merged commit 241ad9c into main Nov 13, 2025
42 of 44 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch Bump the patch version number of this project

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants