Skip to content

security(ci): gate self-hosted jobs to base-repo PRs only - #4841

Closed
SpencerJung wants to merge 1 commit into
manaflow-ai:mainfrom
SpencerJung:fix/385-ci-fork-pr-guard
Closed

SpencerJung wants to merge 1 commit into
manaflow-ai:mainfrom
SpencerJung:fix/385-ci-fork-pr-guard

Conversation

@SpencerJung

@SpencerJung SpencerJung commented May 27, 2026 •

Copy link
Copy Markdown

Summary

  • What changed: Added if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository guards to all four self-hosted (WarpBuild) jobs in .github/workflows/ci.yml ( ests, ests-build-and-lag,
    elease-build, ui-regressions).
  • Why: Fork pull requests currently trigger these jobs on self-hosted macOS runners. An attacker could open a fork PR that modifies workflow steps or build scripts to execute arbitrary commands on the build machine, potentially accessing signing keys, credentials, or internal infrastructure. The guard skips these jobs when the PR originates from a fork, closing the attack surface while preserving CI for internal PRs.

Testing

  • Verified YAML syntax remains valid.
  • Confirmed the if expression is placed immediately after
    uns-on in each affected job.
  • Logic tested: non-PR triggers (push, workflow_dispatch) are unaffected; base-repo PRs continue to run; fork PRs are skipped.

Demo Video

N/A — Infrastructure security fix with no UI or behavioral changes.

Related Issue

Closes #385


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.


Summary by cubic

Gated all self-hosted macOS CI jobs (tests, tests-build-and-lag, release-build, ui-regressions) to run only on base-repo PRs and non-PR events via an if check in .github/workflows/ci.yml. This blocks fork PRs from executing on our runners and protects secrets. Closes #385.

Written for commit 6f0a2af. Summary will update on new commits. Review in cubic

Summary by CodeRabbit

  • Chores
    • Updated CI/CD workflow configuration to optimize build processes and improve efficiency for different types of pull requests.

Review Change Stack

Add explicit fork-PR guards to all self-hosted (WarpBuild) jobs in
ci.yml so that pull requests from forked repositories cannot trigger
arbitrary code execution on the project's build machines. The guard
skips the job when the PR head repository differs from the base
repository.

Fixes manaflow-ai#385.
@vercel

vercel Bot commented May 27, 2026

Copy link
Copy Markdown

@SpencerJung is attempting to deploy a commit to the Manaflow Team on Vercel.

A member of the Team first needs to authorize it.

@coderabbitai

coderabbitai Bot commented May 27, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 9c6d2cf7-c00e-4605-b9ce-412ef649f586

📥 Commits

Reviewing files that changed from the base of the PR and between 3bb505e and 6f0a2af.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

📝 Walkthrough

Walkthrough

This PR adds fork-pull-request guards to four self-hosted CI jobs in the GitHub Actions workflow. Each guard prevents untrusted fork-origin PRs from accessing self-hosted macOS runners and expensive build jobs while preserving execution for same-repository PRs and non-PR events.

Changes

CI Fork-PR Security Guard

Layer / File(s) Summary
Fork-PR guards for self-hosted CI jobs
.github/workflows/ci.yml
Four job-level if: conditions are added using the same fork-PR gating logic. The guards are applied to the macOS test job (warp-macos-15-arm64-6x runner), tests-build-and-lag, release-build, and ui-regressions jobs to run only on non-PR events or same-repository PRs.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 Four guards now stand at the gates with care,
Fork PRs blocked from self-hosted lair,
Runners safe from untrusted command,
Security first—a sturdy land! 🔐✨

🚥 Pre-merge checks | ✅ 17
✅ Passed checks (17 passed)
Check name Status Explanation
Title check ✅ Passed The title 'security(ci): gate self-hosted jobs to base-repo PRs only' directly and clearly summarizes the main change: restricting self-hosted CI jobs to run only on base-repo PRs.
Description check ✅ Passed The description comprehensively covers the required template sections: summary explains what changed and why, testing details verification steps, and a related issue reference. The demo video section is appropriately marked N/A for infrastructure changes.
Linked Issues check ✅ Passed The changes fully address issue #385 by adding the recommended if-guard to all four self-hosted jobs to block fork PRs while preserving CI for base-repo PRs and non-PR triggers.
Out of Scope Changes check ✅ Passed All changes are directly in scope: only the .github/workflows/ci.yml file was modified to add security guards to self-hosted jobs, with no unrelated alterations.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Cmux Swift Actor Isolation ✅ Passed This PR only modifies CI workflow YAML (.github/workflows/ci.yml), not any Swift code. The custom check for Swift actor isolation is not applicable to non-Swift changes.
Cmux Swift Blocking Runtime ✅ Passed PR only modifies CI/CD workflow YAML (.github/workflows/ci.yml); no Swift source code changes made. Custom check for Swift blocking runtime patterns is not applicable.
Cmux No Hacky Sleeps ✅ Passed PR modifies only workflow YAML, which is explicitly out of scope per runtime-no-hacky-sleeps.md. No sleeps, delays, or timing code in production changes.
Cmux Swift Concurrency ✅ Passed PR modifies only .github/workflows/ci.yml (+4/-0 lines) adding security guards to CI jobs; introduces no Swift code or concurrency pattern changes.
Cmux Swift @Concurrent ✅ Passed PR contains no Swift code changes, only YAML CI workflow modifications. The Swift @concurrent annotation check is not applicable to CI configuration files.
Cmux Swift File And Package Boundaries ✅ Passed PR modifies only .github/workflows/ci.yml (YAML), not Swift code. Custom check is scoped to "production Swift changes" and is not applicable.
Cmux Swift Logging ✅ Passed PR is a CI security configuration change, not a production Swift code change. Swift-logging check applies only to Swift modifications.
Cmux User-Facing Error Privacy ✅ Passed CI workflow file changes add only operational job guards (if: conditions). No user-facing errors, alerts, or output added. Allowed as operational infrastructure not shown to end users.
Cmux Full Internationalization ✅ Passed PR changes are CI security guards (.github/workflows/ci.yml only), which are operational infrastructure docs, an explicitly allowed exception to the internationalization check.
Cmux Swiftui State Layout ✅ Passed PR contains only CI/workflow configuration changes to .github/workflows/ci.yml; no SwiftUI code modifications present, so check is not applicable.
Cmux Architecture Rethink ✅ Passed This PR modifies only CI configuration and adds documentation/config files; it contains zero Swift code changes, so the swift-architectural-rethink check does not apply.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed PR contains only CI workflow YAML changes (adding security guards to self-hosted jobs). Custom check for Swift auxiliary window close shortcuts is not applicable as no Swift code changes are present.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@greptile-apps

greptile-apps Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository guards to the four WarpBuild (self-hosted macOS) jobs in ci.yml to prevent fork PRs from executing arbitrary code on the build machines.

  • The guard expression is correct and applied consistently to all four jobs (tests, tests-build-and-lag, release-build, ui-regressions); non-PR triggers like push and workflow_dispatch are unaffected.
  • The other two workflows using WarpBuild runners (build-ghosttykit.yml, ci-macos-compat.yml) are triggered only via workflow_dispatch and are not reachable by fork PRs, so no changes are needed there.
  • The pre-existing tests/test_ci_self_hosted_guard.sh script does not validate the presence of the if: guard, leaving the security fix without automated regression coverage; its header comment also explicitly states that workflow-level fork guards are unnecessary, which now contradicts this change.

Confidence Score: 4/5

The workflow guards are correctly written and close the fork-PR attack surface on self-hosted runners; the main concern is that the pre-existing validation script never checks for the if: condition, so the protection has no automated safety net.

The four if: guards are correct and consistent. The companion test script carries a comment explicitly saying these guards are unnecessary and does not assert their presence, meaning the security fix could be silently removed by a future contributor and CI would not catch it.

tests/test_ci_self_hosted_guard.sh — needs its stale contradictory comment removed and a new assertion added to verify the if: expression is present in each guarded job.

Important Files Changed

Filename Overview
.github/workflows/ci.yml Adds fork-guard if: conditions to all four WarpBuild jobs; logic is correct and symmetric across jobs, but has no automated regression test coverage in the existing guard-test script.
tests/test_ci_self_hosted_guard.sh Pre-existing validation script checks only WarpBuild runner presence — the new fork-guard if: expression is never asserted, and a contradictory comment on lines 5–6 says workflow-level guards are unnecessary.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[CI trigger] --> B{Event type?}
    B -->|push to main| C[All jobs run]
    B -->|workflow_dispatch| C
    B -->|pull_request| D{PR from fork?}
    D -->|No — same repo| E[All jobs run]
    D -->|Yes — fork repo| F[Fork guard check]
    F --> G[Ubuntu jobs run]
    F --> H[WarpBuild jobs SKIPPED]
Loading

Reviews (1): Last reviewed commit: "security(ci): gate self-hosted jobs to b..." | Re-trigger Greptile

@teamleaderleo

Copy link
Copy Markdown
Collaborator

Thanks for this! Fork PRs no longer reach the self-hosted Mac runners landed on main in #14107. You opened this first, so you got there first. Closing since main covers it now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] HIGH-1: Self-hosted CI runner exposed to fork pull requests

2 participants