Skip to content

chore(github/repository/modules): update terraform hashicorp/terraform to v1.12.6 - #836

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/githubrepositorymoduleshashicorpterraform
Aug 26, 2026
Merged

chore(github/repository/modules): update terraform hashicorp/terraform to v1.12.6#836
renovate[bot] merged 1 commit into
mainfrom
renovate/githubrepositorymoduleshashicorpterraform

Conversation

@renovate

@renovate renovate Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
hashicorp/terraform required_version patch 1.12.51.12.6

Release Notes

opentofu/opentofu (hashicorp/terraform)

v1.12.6

Compare Source

SECURITY ADVISORIES:

  • When interacting with OCI Distribution registries for module or provider package installation, earlier versions of OpenTofu could incorrectly resend credentials intended for the original origin to the target of an HTTP redirect. (#​4422)
  • When interacting with an attacker-controlled remote state backend or provider/module registry, tofu init in earlier versions of OpenTofu could potentially cause high CPU usage and/or high memory usage resolving crafted relative URLs in the API responses. (#​4472)

Full Changelog: opentofu/opentofu@v1.12.5...v1.12.6


Configuration

📅 Schedule: (in timezone Asia/Tokyo)

  • Branch creation
    • "before 4am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from panicboat as a code owner August 26, 2026 16:34
@renovate
renovate Bot enabled auto-merge (squash) August 26, 2026 16:34
@panicboat-github-workflow-bot panicboat-github-workflow-bot Bot added the deploy:repository Auto-generated deployment label label Aug 26, 2026
@renovate
renovate Bot merged commit 0174eeb into main Aug 26, 2026
7 checks passed
@renovate
renovate Bot deleted the renovate/githubrepositorymoduleshashicorpterraform branch August 26, 2026 16:46
@github-actions

github-actions Bot commented Aug 26, 2026

Copy link
Copy Markdown

🏗️ Terragrunt plan Results

Service: repository
Environment: master
Status: ✅ Success
Workflow Run: #32992287740

📋 Terragrunt Output
time="2026-08-26T17:07:56Z" level=info msg="download and unarchive the package" aqua_version=2.48.2 env=linux/amd64 exe_name=terragrunt package_name=gruntwork-io/terragrunt package_version=v1.0.2 program=aqua registry=standard
17:07:59.207 INFO   Downloading Terraform configurations from ../../modules into ./.terragrunt-cache/MRqQDSTNrrvxmJqmPn521hGOwpQ/HkNgch3GEVbtijuTQPijduRb1hQ
17:07:59.278 INFO   tofu: Initializing the backend...
17:08:00.472 INFO   tofu: Successfully configured the backend "s3"! OpenTofu will automatically
17:08:00.472 INFO   tofu: use this backend unless the backend configuration changes.
17:08:01.441 INFO   tofu: Initializing provider plugins...
17:08:01.441 INFO   tofu: - Finding integrations/github versions matching "~> 6.13"...
17:08:01.441 INFO   tofu: - Finding hashicorp/aws versions matching "~> 6.60"...
17:08:01.851 INFO   tofu: - Installing integrations/github v6.13.0 to the shared cache directory...
17:08:01.851 INFO   tofu: - Installing hashicorp/aws v6.61.0 to the shared cache directory...
17:08:02.281 INFO   tofu: - Installed integrations/github v6.13.0 (signed, key ID 38027F80D7FD5FB2)
17:08:02.281 INFO   tofu: - Using integrations/github v6.13.0 from the shared cache directory
17:08:06.562 INFO   tofu: - Installed hashicorp/aws v6.61.0 (signed, key ID 0C0AF313E5FD9F80)
17:08:06.562 INFO   tofu: - Using hashicorp/aws v6.61.0 from the shared cache directory
17:08:06.563 INFO   tofu: Providers are signed by their developers.
17:08:06.563 INFO   tofu: If you'd like to know more about provider signing, you can read about it here:
17:08:06.563 INFO   tofu: https://opentofu.org/docs/cli/plugins/signing/
17:08:06.563 INFO   tofu: OpenTofu has created a lock file .terraform.lock.hcl to record the provider
17:08:06.563 INFO   tofu: selections it made above. Include this file in your version control repository
17:08:06.563 INFO   tofu: so that OpenTofu can guarantee to make the same selections by default when
17:08:06.563 INFO   tofu: you run "tofu init" in the future.
17:08:06.563 INFO   tofu: OpenTofu has been successfully initialized!
17:08:06.563 INFO   tofu: You may now begin working with OpenTofu. Try running "tofu plan" to see
17:08:06.563 INFO   tofu: any changes that are required for your infrastructure. All OpenTofu commands
17:08:06.563 INFO   tofu: should now work.
17:08:06.563 INFO   tofu: If you ever set or change modules or backend configuration for OpenTofu,
17:08:06.563 INFO   tofu: rerun this command to reinitialize your working directory. If you forget, other
17:08:06.563 INFO   tofu: commands will detect it and remind you to do so if necessary.
17:08:08.121 STDOUT tofu: Acquiring state lock. This may take a few moments...
17:08:12.332 STDOUT tofu: github_repository.repository["platform"]: Refreshing state... [id=platform]
17:08:12.335 STDOUT tofu: github_repository.repository["monorepo"]: Refreshing state... [id=monorepo]
17:08:12.335 STDOUT tofu: github_repository.repository["panicboat-actions"]: Refreshing state... [id=panicboat-actions]
17:08:12.335 STDOUT tofu: github_repository.repository["dotfiles"]: Refreshing state... [id=dotfiles]
17:08:12.335 STDOUT tofu: github_repository.repository["deploy-actions"]: Refreshing state... [id=deploy-actions]
17:08:12.335 STDOUT tofu: github_repository.repository["ansible"]: Refreshing state... [id=ansible]
17:08:14.209 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["monorepo"]: Refreshing state... [id=/github-repository/monorepo]
17:08:14.211 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["ansible"]: Refreshing state... [id=/github-repository/ansible]
17:08:14.211 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["dotfiles"]: Refreshing state... [id=/github-repository/dotfiles]
17:08:14.211 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["deploy-actions"]: Refreshing state... [id=/github-repository/deploy-actions]
17:08:14.211 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["platform"]: Refreshing state... [id=/github-repository/platform]
17:08:14.212 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["panicboat-actions"]: Refreshing state... [id=/github-repository/panicboat-actions]
17:08:14.698 STDOUT tofu: github_workflow_repository_permissions.repository["monorepo"]: Refreshing state... [id=monorepo]
17:08:14.699 STDOUT tofu: github_workflow_repository_permissions.repository["platform"]: Refreshing state... [id=platform]
17:08:15.065 STDOUT tofu: OpenTofu used the selected providers to generate the following execution
17:08:15.065 STDOUT tofu: plan. Resource actions are indicated with the following symbols:
17:08:15.065 STDOUT tofu:   ~ update in-place (current -> planned)
17:08:15.065 STDOUT tofu: OpenTofu will perform the following actions:
17:08:15.065 STDOUT tofu:   # github_repository.repository["monorepo"] will be updated in-place
17:08:15.065 STDOUT tofu:   ~ resource "github_repository" "repository" {
17:08:15.065 STDOUT tofu:       ~ allow_forking                           = true -> false
17:08:15.065 STDOUT tofu:         id                                      = "monorepo"
17:08:15.065 STDOUT tofu:         name                                    = "monorepo"
17:08:15.065 STDOUT tofu:         # (37 unchanged attributes hidden)
17:08:15.065 STDOUT tofu:         # (1 unchanged block hidden)
17:08:15.065 STDOUT tofu:     }
17:08:15.065 STDOUT tofu:   # github_repository.repository["platform"] will be updated in-place
17:08:15.065 STDOUT tofu:   ~ resource "github_repository" "repository" {
17:08:15.065 STDOUT tofu:       ~ allow_forking                           = true -> false
17:08:15.065 STDOUT tofu:         id                                      = "platform"
17:08:15.065 STDOUT tofu:         name                                    = "platform"
17:08:15.065 STDOUT tofu:         # (37 unchanged attributes hidden)
17:08:15.065 STDOUT tofu:         # (1 unchanged block hidden)
17:08:15.065 STDOUT tofu:     }
17:08:15.065 STDOUT tofu: Plan: 0 to add, 2 to change, 0 to destroy.
17:08:15.066 STDOUT tofu: Warning: Argument is deprecated
17:08:15.066 STDOUT tofu:   with github_repository.repository,
17:08:15.066 STDOUT tofu:   on main.tf line 12, in resource "github_repository" "repository":
17:08:15.066 STDOUT tofu:   12:   vulnerability_alerts = true
17:08:15.066 STDOUT tofu: Use the github_repository_vulnerability_alerts resource instead. This field
17:08:15.066 STDOUT tofu: will be removed in a future version.
17:08:15.066 STDOUT tofu: (and 6 more similar warnings elsewhere)
17:08:15.066 STDOUT tofu: ─────────────────────────────────────────────────────────────────────────────
17:08:15.066 STDOUT tofu: Note: You didn't use the -out option to save this plan, so OpenTofu can't
17:08:15.066 STDOUT tofu: guarantee to take exactly these actions if you run "tofu apply" now.

@github-actions

Copy link
Copy Markdown

🏗️ Terragrunt apply Results

Service: repository
Environment: master
Status: ✅ Success
Workflow Run: #32991362371

📋 Terragrunt Output
time="2026-08-26T17:02:49Z" level=info msg="download and unarchive the package" aqua_version=2.48.2 env=linux/amd64 exe_name=terragrunt package_name=gruntwork-io/terragrunt package_version=v1.0.2 program=aqua registry=standard
17:02:51.316 INFO   Downloading Terraform configurations from ../../modules into ./.terragrunt-cache/MRqQDSTNrrvxmJqmPn521hGOwpQ/HkNgch3GEVbtijuTQPijduRb1hQ
17:02:51.403 INFO   tofu: Initializing the backend...
17:02:52.255 INFO   tofu: Successfully configured the backend "s3"! OpenTofu will automatically
17:02:52.255 INFO   tofu: use this backend unless the backend configuration changes.
17:02:53.065 INFO   tofu: Initializing provider plugins...
17:02:53.065 INFO   tofu: - Finding hashicorp/aws versions matching "~> 6.60"...
17:02:53.065 INFO   tofu: - Finding integrations/github versions matching "~> 6.13"...
17:02:53.717 INFO   tofu: - Installing integrations/github v6.13.0 to the shared cache directory...
17:02:53.741 INFO   tofu: - Installing hashicorp/aws v6.61.0 to the shared cache directory...
17:02:54.267 INFO   tofu: - Installed integrations/github v6.13.0 (signed, key ID 38027F80D7FD5FB2)
17:02:54.267 INFO   tofu: - Using integrations/github v6.13.0 from the shared cache directory
17:02:58.442 INFO   tofu: - Installed hashicorp/aws v6.61.0 (signed, key ID 0C0AF313E5FD9F80)
17:02:58.442 INFO   tofu: - Using hashicorp/aws v6.61.0 from the shared cache directory
17:02:58.443 INFO   tofu: Providers are signed by their developers.
17:02:58.443 INFO   tofu: If you'd like to know more about provider signing, you can read about it here:
17:02:58.443 INFO   tofu: https://opentofu.org/docs/cli/plugins/signing/
17:02:58.443 INFO   tofu: OpenTofu has created a lock file .terraform.lock.hcl to record the provider
17:02:58.443 INFO   tofu: selections it made above. Include this file in your version control repository
17:02:58.443 INFO   tofu: so that OpenTofu can guarantee to make the same selections by default when
17:02:58.443 INFO   tofu: you run "tofu init" in the future.
17:02:58.443 INFO   tofu: OpenTofu has been successfully initialized!
17:02:58.443 INFO   tofu: You may now begin working with OpenTofu. Try running "tofu plan" to see
17:02:58.443 INFO   tofu: any changes that are required for your infrastructure. All OpenTofu commands
17:02:58.443 INFO   tofu: should now work.
17:02:58.443 INFO   tofu: If you ever set or change modules or backend configuration for OpenTofu,
17:02:58.443 INFO   tofu: rerun this command to reinitialize your working directory. If you forget, other
17:02:58.443 INFO   tofu: commands will detect it and remind you to do so if necessary.
17:03:04.668 STDOUT tofu: github_repository.repository["monorepo"]: Refreshing state... [id=monorepo]
17:03:04.668 STDOUT tofu: github_repository.repository["deploy-actions"]: Refreshing state... [id=deploy-actions]
17:03:04.670 STDOUT tofu: github_repository.repository["ansible"]: Refreshing state... [id=ansible]
17:03:04.671 STDOUT tofu: github_repository.repository["panicboat-actions"]: Refreshing state... [id=panicboat-actions]
17:03:04.672 STDOUT tofu: github_repository.repository["dotfiles"]: Refreshing state... [id=dotfiles]
17:03:04.673 STDOUT tofu: github_repository.repository["platform"]: Refreshing state... [id=platform]
17:03:06.811 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["monorepo"]: Refreshing state... [id=/github-repository/monorepo]
17:03:06.812 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["panicboat-actions"]: Refreshing state... [id=/github-repository/panicboat-actions]
17:03:06.813 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["deploy-actions"]: Refreshing state... [id=/github-repository/deploy-actions]
17:03:06.813 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["dotfiles"]: Refreshing state... [id=/github-repository/dotfiles]
17:03:06.813 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["ansible"]: Refreshing state... [id=/github-repository/ansible]
17:03:06.813 STDOUT tofu: aws_cloudwatch_log_group.github_repository_logs["platform"]: Refreshing state... [id=/github-repository/platform]
17:03:07.408 STDOUT tofu: github_workflow_repository_permissions.repository["monorepo"]: Refreshing state... [id=monorepo]
17:03:07.410 STDOUT tofu: github_workflow_repository_permissions.repository["platform"]: Refreshing state... [id=platform]
17:03:07.892 STDOUT tofu: OpenTofu used the selected providers to generate the following execution
17:03:07.892 STDOUT tofu: plan. Resource actions are indicated with the following symbols:
17:03:07.892 STDOUT tofu:   ~ update in-place (current -> planned)
17:03:07.892 STDOUT tofu: OpenTofu will perform the following actions:
17:03:07.892 STDOUT tofu:   # github_repository.repository["monorepo"] will be updated in-place
17:03:07.892 STDOUT tofu:   ~ resource "github_repository" "repository" {
17:03:07.892 STDOUT tofu:       ~ allow_forking                           = true -> false
17:03:07.892 STDOUT tofu:         id                                      = "monorepo"
17:03:07.892 STDOUT tofu:         name                                    = "monorepo"
17:03:07.892 STDOUT tofu:         # (37 unchanged attributes hidden)
17:03:07.892 STDOUT tofu:         # (1 unchanged block hidden)
17:03:07.892 STDOUT tofu:     }
17:03:07.892 STDOUT tofu:   # github_repository.repository["platform"] will be updated in-place
17:03:07.893 STDOUT tofu:   ~ resource "github_repository" "repository" {
17:03:07.893 STDOUT tofu:       ~ allow_forking                           = true -> false
17:03:07.893 STDOUT tofu:         id                                      = "platform"
17:03:07.893 STDOUT tofu:         name                                    = "platform"
17:03:07.893 STDOUT tofu:         # (37 unchanged attributes hidden)
17:03:07.893 STDOUT tofu:         # (1 unchanged block hidden)
17:03:07.893 STDOUT tofu:     }
17:03:07.893 STDOUT tofu: Plan: 0 to add, 2 to change, 0 to destroy.
17:03:08.239 STDOUT tofu: github_repository.repository["monorepo"]: Modifying... [id=monorepo]
17:03:08.240 STDOUT tofu: github_repository.repository["platform"]: Modifying... [id=platform]
17:03:11.643 STDOUT tofu: github_repository.repository["monorepo"]: Modifications complete after 4s [id=monorepo]
17:03:11.847 STDOUT tofu: github_repository.repository["platform"]: Modifications complete after 4s [id=platform]
17:03:12.484 STDOUT tofu: Warning: Argument is deprecated
17:03:12.484 STDOUT tofu:   with github_repository.repository,
17:03:12.484 STDOUT tofu:   on main.tf line 12, in resource "github_repository" "repository":
17:03:12.484 STDOUT tofu:   12:   vulnerability_alerts = true
17:03:12.484 STDOUT tofu: Use the github_repository_vulnerability_alerts resource instead. This field
17:03:12.484 STDOUT tofu: will be removed in a future version.
17:03:12.484 STDOUT tofu: (and 8 more similar warnings elsewhere)
17:03:12.710 STDOUT tofu: Apply complete! Resources: 0 added, 2 changed, 0 destroyed.
17:03:12.711 STDOUT tofu: Outputs:
17:03:12.711 STDOUT tofu: cloudwatch_log_group_arns = {
17:03:12.711 STDOUT tofu:   "ansible" = "arn:aws:logs:ap-northeast-1:559744160976:log-group:/github-repository/ansible"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "arn:aws:logs:ap-northeast-1:559744160976:log-group:/github-repository/deploy-actions"
17:03:12.711 STDOUT tofu:   "dotfiles" = "arn:aws:logs:ap-northeast-1:559744160976:log-group:/github-repository/dotfiles"
17:03:12.711 STDOUT tofu:   "monorepo" = "arn:aws:logs:ap-northeast-1:559744160976:log-group:/github-repository/monorepo"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "arn:aws:logs:ap-northeast-1:559744160976:log-group:/github-repository/panicboat-actions"
17:03:12.711 STDOUT tofu:   "platform" = "arn:aws:logs:ap-northeast-1:559744160976:log-group:/github-repository/platform"
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: cloudwatch_log_group_names = {
17:03:12.711 STDOUT tofu:   "ansible" = "/github-repository/ansible"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "/github-repository/deploy-actions"
17:03:12.711 STDOUT tofu:   "dotfiles" = "/github-repository/dotfiles"
17:03:12.711 STDOUT tofu:   "monorepo" = "/github-repository/monorepo"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "/github-repository/panicboat-actions"
17:03:12.711 STDOUT tofu:   "platform" = "/github-repository/platform"
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: repository_full_names = {
17:03:12.711 STDOUT tofu:   "ansible" = "panicboat/ansible"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "panicboat/deploy-actions"
17:03:12.711 STDOUT tofu:   "dotfiles" = "panicboat/dotfiles"
17:03:12.711 STDOUT tofu:   "monorepo" = "panicboat/monorepo"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "panicboat/panicboat-actions"
17:03:12.711 STDOUT tofu:   "platform" = "panicboat/platform"
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: repository_html_urls = {
17:03:12.711 STDOUT tofu:   "ansible" = "https://github.com/panicboat/ansible"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "https://github.com/panicboat/deploy-actions"
17:03:12.711 STDOUT tofu:   "dotfiles" = "https://github.com/panicboat/dotfiles"
17:03:12.711 STDOUT tofu:   "monorepo" = "https://github.com/panicboat/monorepo"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "https://github.com/panicboat/panicboat-actions"
17:03:12.711 STDOUT tofu:   "platform" = "https://github.com/panicboat/platform"
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: repository_http_clone_urls = {
17:03:12.711 STDOUT tofu:   "ansible" = "https://github.com/panicboat/ansible.git"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "https://github.com/panicboat/deploy-actions.git"
17:03:12.711 STDOUT tofu:   "dotfiles" = "https://github.com/panicboat/dotfiles.git"
17:03:12.711 STDOUT tofu:   "monorepo" = "https://github.com/panicboat/monorepo.git"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "https://github.com/panicboat/panicboat-actions.git"
17:03:12.711 STDOUT tofu:   "platform" = "https://github.com/panicboat/platform.git"
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: repository_ids = {
17:03:12.711 STDOUT tofu:   "ansible" = 880089351
17:03:12.711 STDOUT tofu:   "deploy-actions" = 1014666976
17:03:12.711 STDOUT tofu:   "dotfiles" = 880093624
17:03:12.711 STDOUT tofu:   "monorepo" = 807388271
17:03:12.711 STDOUT tofu:   "panicboat-actions" = 1221231096
17:03:12.711 STDOUT tofu:   "platform" = 994278495
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: repository_node_ids = {
17:03:12.711 STDOUT tofu:   "ansible" = "R_kgDONHUZBw"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "R_kgDOPHqW4A"
17:03:12.711 STDOUT tofu:   "dotfiles" = "R_kgDONHUpuA"
17:03:12.711 STDOUT tofu:   "monorepo" = "R_kgDOMB_Ebw"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "R_kgDOSMqB-A"
17:03:12.711 STDOUT tofu:   "platform" = "R_kgDOO0N8Xw"
17:03:12.711 STDOUT tofu: }
17:03:12.711 STDOUT tofu: repository_ssh_clone_urls = {
17:03:12.711 STDOUT tofu:   "ansible" = "git@github.com:panicboat/ansible.git"
17:03:12.711 STDOUT tofu:   "deploy-actions" = "git@github.com:panicboat/deploy-actions.git"
17:03:12.711 STDOUT tofu:   "dotfiles" = "git@github.com:panicboat/dotfiles.git"
17:03:12.711 STDOUT tofu:   "monorepo" = "git@github.com:panicboat/monorepo.git"
17:03:12.711 STDOUT tofu:   "panicboat-actions" = "git@github.com:panicboat/panicboat-actions.git"
17:03:12.711 STDOUT tofu:   "platform" = "git@github.com:panicboat/platform.git"
17:03:12.711 STDOUT tofu: }

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deploy:repository Auto-generated deployment label 🤖 renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants