Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ on:
jobs:
build-production:
runs-on: ubuntu-24.04
if: github.ref_name == github.event.repository.default_branch
if: github.event_name == 'pull_request' || github.ref_name == github.event.repository.default_branch

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The workflow change allows pull requests to trigger a job that may overwrite the production :latest Docker image, as there is no condition to prevent this.
Severity: CRITICAL

Suggested Fix

Add a condition to the image push steps to ensure they only execute on pushes to the default branch, not on pull request events. For example, change the step's condition to if: github.event_name == 'push' && github.ref_name == github.event.repository.default_branch. This will prevent PRs from overwriting the production image.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: .github/workflows/image.yml#L12

Potential issue: The workflow condition was changed to `if: github.event_name ==
'pull_request' || github.ref_name == github.event.repository.default_branch`, allowing
the `build-production` job to run on pull requests. This job pushes to production Google
Artifact Registries and uses `tag_latest: true`. Because there is no explicit condition
to prevent pushes on pull request events, a build triggered by a PR could overwrite the
production `:latest` Docker image. This could result in an unvetted or unstable version
of the application being deployed to production.

name: Build and push production image
permissions:
contents: read
Expand Down
7 changes: 4 additions & 3 deletions gocd/pipelines/reload.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,13 +25,14 @@ pipelines:
jobs:
checks:
environment_variables:
# Required for checkruns.
GITHUB_TOKEN: "{{SECRET:[devinfra-github][token]}}"
# Required for checkruns2.
GITHUB_APP_ID: "{{SECRET:[devinfra-github][app_id]}}"
GITHUB_APP_PRIVATE_KEY: "{{SECRET:[devinfra-github][private_key]}}"
timeout: 1200
elastic_profile_id: reload
tasks:
- script: |
checks-githubactions-checkruns \
checks-githubactions-checkruns2 \
getsentry/reload \
${GO_REVISION_RELOAD_REPO} \
Comment thread
joshuarli marked this conversation as resolved.
"Build and push production image"
Expand Down
Loading