Repository navigation
security(ci): gate self-hosted jobs to base-repo PRs only - #4841
SpencerJung wants to merge 1 commit into
Conversation
Add explicit fork-PR guards to all self-hosted (WarpBuild) jobs in ci.yml so that pull requests from forked repositories cannot trigger arbitrary code execution on the project's build machines. The guard skips the job when the PR head repository differs from the base repository. Fixes manaflow-ai#385.
|
@SpencerJung is attempting to deploy a commit to the Manaflow Team on Vercel. A member of the Team first needs to authorize it. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis PR adds fork-pull-request guards to four self-hosted CI jobs in the GitHub Actions workflow. Each guard prevents untrusted fork-origin PRs from accessing self-hosted macOS runners and expensive build jobs while preserving execution for same-repository PRs and non-PR events. ChangesCI Fork-PR Security Guard
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 17✅ Passed checks (17 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR adds
Confidence Score: 4/5The workflow guards are correctly written and close the fork-PR attack surface on self-hosted runners; the main concern is that the pre-existing validation script never checks for the The four tests/test_ci_self_hosted_guard.sh — needs its stale contradictory comment removed and a new assertion added to verify the Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[CI trigger] --> B{Event type?}
B -->|push to main| C[All jobs run]
B -->|workflow_dispatch| C
B -->|pull_request| D{PR from fork?}
D -->|No — same repo| E[All jobs run]
D -->|Yes — fork repo| F[Fork guard check]
F --> G[Ubuntu jobs run]
F --> H[WarpBuild jobs SKIPPED]
Reviews (1): Last reviewed commit: "security(ci): gate self-hosted jobs to b..." | Re-trigger Greptile |
|
Thanks for this! Fork PRs no longer reach the self-hosted Mac runners landed on main in #14107. You opened this first, so you got there first. Closing since main covers it now. |
Summary
elease-build, ui-regressions).
Testing
uns-on in each affected job.
Demo Video
N/A — Infrastructure security fix with no UI or behavioral changes.
Related Issue
Closes #385
Need help on this PR? Tag
@codesmithwith what you need. Autofix is disabled.Summary by cubic
Gated all self-hosted macOS CI jobs (tests, tests-build-and-lag, release-build, ui-regressions) to run only on base-repo PRs and non-PR events via an
ifcheck in.github/workflows/ci.yml. This blocks fork PRs from executing on our runners and protects secrets. Closes #385.Written for commit 6f0a2af. Summary will update on new commits. Review in cubic
Summary by CodeRabbit