chore: update fullsend shim workflow - #144
fullsend-ai-fullsend[bot] wants to merge 1 commit into
Conversation
|
🤖 Finished Review · ✅ Success · Started 9:26 PM UTC · Completed 9:36 PM UTC Commit: |
ReviewFindingsHigh
Medium
Low
Next steps:
Previous runReviewFindingsCritical
High
Medium
Next steps:
Previous run (2)ReviewFindingsHigh
Medium
Low
Next steps:
Previous run (3)ReviewFindingsHigh
Medium
Low
Next steps:
Previous run (4)ReviewFindingsHigh
Medium
Next steps:
Previous run (5)ReviewFindingsHigh
Low
Next steps:
Previous run (6)ReviewFindingsHigh
Medium
Labels: PR removes SHA pinning from a privileged GitHub Actions workflow reference, weakening supply chain security controls on a protected infrastructure file Next steps:
|
1a29955 to
78ba237
Compare
|
🤖 Finished Review · ✅ Success · Started 7:48 PM UTC · Completed 7:59 PM UTC Commit: |
78ba237 to
c346547
Compare
|
🤖 Finished Review · ✅ Success · Started 5:15 PM UTC · Completed 5:29 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.06 |
|
Risk Assessment: moderate (2/5) DetailsSmall CI workflow sync (1 file, 40 lines) by a bot author carries moderate risk due to the CI_WORKFLOW_CHANGED signal and a protected path hit, offset by minimal change size, no security-sensitive files, and a clean regression history — consistent with the prior assessment, all signals unchanged. Previous runRisk Assessment: moderate (2/5) DetailsSmall CI workflow sync (1 file, 40 lines) by a bot author carries moderate risk due to the CI_WORKFLOW_CHANGED signal and a protected path hit, offset by minimal change size, no security-sensitive files, and a clean regression history. Previous run (2)Risk Assessment: moderate (2/5) DetailsAnchored to prior score of 2; Tier 1 signals are unchanged (1 CI workflow file, PROTECTED_PATH_COUNT=1, CI_WORKFLOW_CHANGED=true, bot author) and Tier 2 confirms low churn with no regressions — CI_WORKFLOW_CHANGED and the human-applied 'Possible security concern' label remain the primary risk drivers warranting standard review. Previous run (3)Risk Assessment: moderate (2/5) DetailsSmall CI workflow sync by a bot author with low churn and no regressions matches the prior assessment; CI_WORKFLOW_CHANGED and a human-applied 'Possible security concern' label remain the primary risk drivers warranting standard review to verify the template re-sync does not introduce unintended workflow permissions or step changes. Previous run (4)Risk Assessment: moderate (2/5) DetailsSmall CI workflow sync by a bot author with low churn and no regressions, but the CI_WORKFLOW_CHANGED signal and a human-applied 'Possible security concern' label warrant standard review to verify the template re-sync does not introduce unintended workflow permissions or step modifications. |
c346547 to
b30d3b4
Compare
|
🤖 Finished Review · ✅ Success · Started 5:41 PM UTC · Completed 5:57 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.20 |
b30d3b4 to
b189a2f
Compare
|
🤖 Finished Review · ✅ Success · Started 7:05 PM UTC · Completed 7:20 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.53 |
b189a2f to
866ba9a
Compare
|
🤖 Finished Review · ✅ Success · Started 3:01 PM UTC · Completed 3:15 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.11 |
Update the shim workflow to match the current template in the .fullsend config repo.
866ba9a to
643df73
Compare
|
🤖 Review · ❌ Terminated · Started 6:33 PM UTC · Ended 6:48 PM UTC Commit: |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #144 +/- ##
==========================================
+ Coverage 48.05% 48.08% +0.02%
==========================================
Files 154 154
Lines 10501 10501
==========================================
+ Hits 5046 5049 +3
+ Misses 5237 5235 -2
+ Partials 218 217 -1
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
| github.event_name != 'issue_comment' | ||
| || github.event.comment.user.type != 'Bot' | ||
| uses: konflux-ci/.fullsend/.github/workflows/dispatch.yml@701e62a9c6f104ed68f8d4085d9c3b8bad3a82e4 # main | ||
| uses: konflux-ci/.fullsend/.github/workflows/dispatch.yml@main |
There was a problem hiding this comment.
[high] permission-expansion
Reusable workflow reference changed from a pinned commit SHA (701e62a9c6f104ed68f8d4085d9c3b8bad3a82e4) to a mutable branch reference (@main). The dispatch job inherits workflow-level permissions including actions:write and id-token:write (OIDC token minting). With a pinned SHA, the exact code that runs is immutable and auditable. With @main, any actor with write access to konflux-ci/.fullsend's main branch can modify dispatch.yml to exfiltrate OIDC tokens or abuse actions:write to trigger further workflows. The base branch code included a '# main' comment alongside the SHA, demonstrating the pinning was deliberate.
Suggested fix: Pin the reusable workflow reference to a specific commit SHA with a branch comment, e.g., @ # main. If the upstream template genuinely uses @main, that requires explicit human decision and documentation.
| types: [created] | ||
| pull_request_target: | ||
| types: [opened, synchronize, ready_for_review, closed] | ||
| types: [closed] |
There was a problem hiding this comment.
[medium] CI coverage regression
The pull_request_target trigger types were reduced from [opened, synchronize, ready_for_review, closed] to [closed]. The dispatch job will no longer forward PR-open, push, and ready-for-review events to dispatch.yml. If dispatch.yml contains stages handling these actions, they will silently stop triggering for this repository. The external dispatch.yml (in konflux-ci/.fullsend) cannot be verified from this repo. The PR description characterizes this as a template sync but does not explicitly call out this functional behavioral change.
Suggested fix: Confirm that dispatch.yml in the .fullsend config repo no longer has stage branches that act on 'opened', 'synchronize', or 'ready_for_review' pull_request_target actions before merging.
| with: | ||
| event_action: ${{ github.event.action }} | ||
|
|
||
| review-denied: |
There was a problem hiding this comment.
[medium] logic-error
The new review-denied job and the dispatch job both fire in parallel for the same issue_comment event. When an unauthorized user posts '/fs-review' or '/fullsend-review', review-denied posts a denial comment, but the dispatch job simultaneously forwards the event to dispatch.yml with no authorization filter. If dispatch.yml does not independently enforce authorization, the review will execute despite the denial message. The review-denied job is advisory only — it cannot block the dispatch job.
Suggested fix: Verify that dispatch.yml independently enforces authorization for /fs-review and /fullsend-review commands.
| with: | ||
| event_action: ${{ github.event.action }} | ||
|
|
||
| review-denied: |
There was a problem hiding this comment.
[low] architectural-coherence
The new review-denied job is architecturally consistent with the existing stop-fix job (same permissions pattern, same use of env: for untrusted input, same author_association check). Its addition genuinely fits the 'sync' description.
|
🤖 Finished Review · ✅ Success · Started 6:33 PM UTC · Completed 6:48 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.34 |
This PR updates the fullsend shim workflow to match the current template in the
.fullsendconfig repo.The shim content has drifted from the template — this brings it back in sync.