Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/build-fork.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
name: Publish Fork Image to GHCR
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

on:
push:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/claude.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
name: Claude Code
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Concurrency group cancels all Claude runs across PRs

High Severity

For issue_comment and pull_request_review_comment events, github.ref is always the default branch (e.g., refs/heads/main), not the PR branch. This means every Claude Code invocation shares the same concurrency group (Claude Code-refs/heads/main). With cancel-in-progress: true, any new comment on any issue or PR — even one that doesn't mention @claude — triggers the workflow, joins the shared group, and cancels the in-progress run before the job-level if condition filtering for @claude is evaluated. This effectively makes Claude unable to complete any task if comments arrive on other issues/PRs.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit d20ed5e. Configure here.


on:
issue_comment:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
name: Publish to Docker Hub
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

on:
push:
Expand Down Expand Up @@ -27,7 +30,7 @@

permissions:
contents: read
packages: write

Check warning on line 33 in .github/workflows/docker-publish.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Move this write permission from workflow level to job level.

See more on https://sonarcloud.io/project/issues?id=KooshaPari_OmniRoute&issues=AZ5uYiqK0m7TpZSVnWjC&open=AZ5uYiqK0m7TpZSVnWjC&pullRequest=8

jobs:
prepare:
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/electron-release.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
name: Build Electron Desktop App
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

on:
push:
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/lock-released-branch.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
name: Lock released branch

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security workflow can be cancelled mid-execution by dispatch

Medium Severity

This security-critical workflow locks release branches to prevent post-release commits. With cancel-in-progress: true, two workflow_dispatch calls from the same ref (e.g., dispatched from main to lock different tags) would share the same concurrency group, causing the first lock operation to be cancelled before completing. A branch could remain unlocked, violating the "Hard Rule #18" this workflow is explicitly designed to enforce.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit d20ed5e. Configure here.


# Two responsibilities (defense in depth — Hard Rule #18 enforcement):
#
# 1. `on: release: published` — when a GitHub Release publishes tag v3.X.Y,
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/npm-publish.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
name: Publish to npm
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reusable workflow concurrency causes deadlock when called via workflow_call

High Severity

npm-publish.yml is called as a reusable workflow via workflow_call from electron-release.yml. When called this way, github.workflow inherits the caller's name ("Build Electron Desktop App"), making both workflows resolve to the same concurrency group. GitHub Actions detects this as a deadlock — the caller is in-progress in the group while the called workflow tries to enter it — and the reusable workflow fails immediately. This breaks npm publishing when triggered through the electron release flow.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit d20ed5e. Configure here.


on:
# 'released' (not 'published') so editing/re-publishing old releases does NOT
Expand Down Expand Up @@ -39,8 +42,8 @@

permissions:
contents: read
id-token: write

Check warning on line 45 in .github/workflows/npm-publish.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Move this write permission from workflow level to job level.

See more on https://sonarcloud.io/project/issues?id=KooshaPari_OmniRoute&issues=AZ5uYilH0m7TpZSVnWi8&open=AZ5uYilH0m7TpZSVnWi8&pullRequest=8
packages: write

Check warning on line 46 in .github/workflows/npm-publish.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Move this write permission from workflow level to job level.

See more on https://sonarcloud.io/project/issues?id=KooshaPari_OmniRoute&issues=AZ5uYilH0m7TpZSVnWi7&open=AZ5uYilH0m7TpZSVnWi7&pullRequest=8

env:
NPM_PUBLISH_NODE_VERSION: "24"
Expand Down
Loading