Skip to content

fix: pipeline - #443

Merged
RambokDev merged 3 commits into
mainfrom
fix/pipeline
Aug 1, 2026
Merged

RambokDev merged 3 commits into
mainfrom
fix/pipeline

Conversation

@RambokDev

@RambokDev RambokDev commented Aug 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • New Features

    • Added automated Plumber checks for pull requests and updates to the main branch.
    • Enabled security scoring during workflow validation.
  • Documentation

    • Added a Plumber Score badge to the project README.
  • Chores

    • Strengthened workflow permissions using least-privilege access.
    • Improved build, release, and security workflow reliability by pinning automation tools to fixed versions.
    • Enhanced protection against unexpected changes in third-party workflow actions.

@coderabbitai

coderabbitai Bot commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 95057eb1-4f10-497d-8cd9-e76a7d33129c

📥 Commits

Reviewing files that changed from the base of the PR and between 30cc8c1 and e64c872.

📒 Files selected for processing (1)
  • README.md
📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: build-image
  • GitHub Check: plumber
  • GitHub Check: Analyze (javascript-typescript)
🔇 Additional comments (2)
README.md (2)

14-14: LGTM!


40-40: LGTM!


📝 Walkthrough

Walkthrough

The workflows now declare explicit permissions and pin external GitHub Actions to commit SHAs. A new Plumber workflow runs on pull requests and pushes to main. The release workflow passes the pull request title through TITLE. The README adds a Plumber Score badge.

Changes

Workflow hardening

Layer / File(s) Summary
Permissions and immutable action references
.github/workflows/discord.yml, .github/workflows/docker.yml, .github/workflows/e2e.yml, .github/workflows/ghcr.yml, .github/workflows/helm.yml, .github/workflows/release.yml, .github/workflows/security.yml
Existing workflows add explicit permissions and replace mutable action tags or branch references with commit-pinned versions.
Plumber workflow and score badge
.github/workflows/plumber.yml, README.md
The Plumber workflow runs on pull requests and pushes to main. It checks out the repository, enables push scoring, and adds a Plumber Score badge to the README.
Release title environment input
.github/workflows/release.yml
The release skip check receives the pull request title through the TITLE environment variable.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: asuniia

Poem

A rabbit pins each action tight,
And grants workflows the needed right.
Plumber hops through every PR,
While release titles travel clear.
A score badge shines in README light.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Title check ❓ Inconclusive The title identifies pipeline changes but does not describe the workflow hardening, action pinning, or Plumber workflow additions. Use a specific title such as "harden CI workflows and pin GitHub Actions".
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/pipeline

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/helm.yml:
- Around line 12-15: Remove the unused workflow-wide packages: write permission
from the permissions block in the Helm workflow, unless publish-helm is
explicitly changed to authenticate with github.token; if retained, scope
packages: write only to the publish-helm job.

In @.github/workflows/plumber.yml:
- Around line 17-18: Pin every mutable GitHub Actions reference to its full
commit SHA, preserving the existing action versions and workflow behavior.
Update all affected uses entries in .github/workflows/plumber.yml (17-18),
.github/workflows/docker.yml (53-56), .github/workflows/e2e.yml (26-36),
.github/workflows/ghcr.yml (52-63), .github/workflows/helm.yml (24-25),
.github/workflows/release.yml (54-55), and .github/workflows/security.yml
(15-15), including checkout, Docker, artifact, setup-node,
create-github-app-token, and workflow-call references; remove mutable tags or
branch references.

In @.github/workflows/security.yml:
- Around line 14-15: Disable persisted checkout credentials by setting
persist-credentials to false on the checkout steps in
.github/workflows/security.yml at lines 14-15 and 26, and
.github/workflows/plumber.yml at lines 17-18. Apply the change to each
actions/checkout invocation before downstream scanning steps.
- Around line 7-8: Update the security workflow permissions for the
secrets-gitleaks job: retain contents: read and add pull-requests: write so
Gitleaks can post comments using GITHUB_TOKEN. Do not change permissions for
unrelated jobs.
- Line 29: Update the gitleaks action reference in the security workflow from
the pinned v2 commit to the verified Gitleaks v3 commit, and update the version
annotation accordingly. Keep the existing workflow step and configuration
unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 5360a951-a183-4e75-b3cd-f28700a3a071

📥 Commits

Reviewing files that changed from the base of the PR and between 6376680 and 30cc8c1.

📒 Files selected for processing (8)
  • .github/workflows/discord.yml
  • .github/workflows/docker.yml
  • .github/workflows/e2e.yml
  • .github/workflows/ghcr.yml
  • .github/workflows/helm.yml
  • .github/workflows/plumber.yml
  • .github/workflows/release.yml
  • .github/workflows/security.yml
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: Plumber
  • GitHub Check: build-image
  • GitHub Check: plumber
🧰 Additional context used
🪛 YAMLlint (1.37.1)
.github/workflows/plumber.yml

[warning] 3-3: truthy value should be one of [false, true]

(truthy)


[error] 6-6: too many spaces inside brackets

(brackets)


[error] 6-6: too many spaces inside brackets

(brackets)

🪛 zizmor (1.28.0)
.github/workflows/plumber.yml

[warning] 17-17: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[warning] 10-10: overly broad permissions (excessive-permissions): security-events: write is overly broad at the workflow level

(excessive-permissions)


[error] 11-11: overly broad permissions (excessive-permissions): id-token: write is overly broad at the workflow level

(excessive-permissions)


[error] 17-17: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[warning] 10-10: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment

(undocumented-permissions)


[info] 14-14: workflow or action definition without a name (anonymous-definition): this job

(anonymous-definition)


[warning] 3-6: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting

(concurrency-limits)

.github/workflows/security.yml

[warning] 14-14: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 14-14: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[info] 11-11: workflow or action definition without a name (anonymous-definition): this job

(anonymous-definition)

.github/workflows/helm.yml

[error] 14-14: overly broad permissions (excessive-permissions): packages: write is overly broad at the workflow level

(excessive-permissions)


[warning] 14-14: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment

(undocumented-permissions)

🔇 Additional comments (6)
.github/workflows/discord.yml (1)

24-26: LGTM!

.github/workflows/docker.yml (1)

34-36: LGTM!

Also applies to: 70-70, 106-106, 130-130

.github/workflows/e2e.yml (1)

48-48: LGTM!

.github/workflows/ghcr.yml (1)

106-117: LGTM!

.github/workflows/release.yml (1)

22-25: LGTM!

.github/workflows/plumber.yml (1)

8-11: LGTM!

Comment thread .github/workflows/helm.yml
Comment thread .github/workflows/plumber.yml
Comment thread .github/workflows/security.yml
Comment thread .github/workflows/security.yml
Comment thread .github/workflows/security.yml
@RambokDev
RambokDev merged commit c2f00fa into main Aug 1, 2026
9 checks passed
@RambokDev
RambokDev deleted the fix/pipeline branch August 1, 2026 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants