Skip to content

chore: promote staging to staging-promote/427783da-24468358894 (2026-04-15 22:13 UTC) - #2510

Merged
henrypark133 merged 1 commit into
mainfrom
staging-promote/b3478cf3-24481112105
Apr 18, 2026
Merged

henrypark133 merged 1 commit into
mainfrom
staging-promote/b3478cf3-24481112105

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Apr 15, 2026 •

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: a53eac5c2dec6b6cd5c08189086093fde64aa9cb..b3478cf3816a99d66313f1b89a0c3fa70219d7c3
Promotion branch: staging-promote/b3478cf3-24481112105
Base: staging-promote/427783da-24468358894
Triggered by: Staging CI batch at 2026-04-15 22:13 UTC

Commits in this batch (51):

Current commits in this promotion (0)

Current base: main
Current head: staging-promote/b3478cf3-24481112105
Current range: origin/main..origin/staging-promote/b3478cf3-24481112105

  • (no non-merge commits in range)

Auto-updated by staging promotion metadata workflow

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

* ci: add release image rebuild workflow

* ci: tighten release image rebuild checks
@github-actions github-actions Bot added scope: ci CI/CD workflows size: M 50-199 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Apr 15, 2026
@claude

claude Bot commented Apr 15, 2026

Copy link
Copy Markdown

Code review

Found 7 issues:

  1. [HIGH:85] Missing error handling for git rev-list command

    • Line 57: git rev-list -n1 "${EXPECTED_REF}" does not check exit code
    • If the tag doesn't exist in the repository, the command silently fails and EXPECTED_COMMIT becomes empty
    • No set -e to halt execution on errors
    • The comparison on line 59 would pass with unset variables, allowing invalid commits through

    EXPECTED_COMMIT=$(git rev-list -n1 "${EXPECTED_REF}")
    ACTUAL_COMMIT=$(git rev-parse HEAD)
    if [[ "${ACTUAL_COMMIT}" != "${EXPECTED_COMMIT}" ]]; then
    echo "::error::Checked out commit '${ACTUAL_COMMIT}' does not match release tag '${EXPECTED_REF}' (${EXPECTED_COMMIT})"

  2. [MEDIUM:85] Undocumented source_ref format requirement

    • Input description (lines 5-7) does not specify that source_ref must be a git tag in format ironclaw-vX.Y.Z
    • The check at line 45 enforces this but error messaging is confusing for users who provide just v1.2.3 or a branch name
    • Creates poor UX where validation fails but the expected format isn't clearly documented upfront

    inputs:
    source_ref:
    description: "Tag or branch to build from"
    required: true
    type: string
    tag:
    description: "Docker image tag to publish"
    required: true

  3. [MEDIUM:80] Missing explicit git operation error handling

    • Lines 57-58: Both git rev-list and git rev-parse commands lack error checking
    • If the repository state is corrupted or the tag is missing, the script continues with empty variables
    • Results in misleading error messages rather than clear failure diagnostics

    EXPECTED_COMMIT=$(git rev-list -n1 "${EXPECTED_REF}")
    ACTUAL_COMMIT=$(git rev-parse HEAD)
    if [[ "${ACTUAL_COMMIT}" != "${EXPECTED_COMMIT}" ]]; then
    echo "::error::Checked out commit '${ACTUAL_COMMIT}' does not match release tag '${EXPECTED_REF}' (${EXPECTED_COMMIT})"
    exit 1

  4. [MEDIUM:70] Overly permissive workflow dispatch access

    • No approval mechanism required to trigger image rebuilds and Docker pushes
    • Any repository maintainer can invoke arbitrary rebuilds
    • While validation restricts to existing git refs, this is still a significant attack surface without additional approval gates

    on:
    workflow_dispatch:
    inputs:
    source_ref:
    description: "Tag or branch to build from"
    required: true
    type: string
    tag:
    description: "Docker image tag to publish"
    required: true
    type: string

  5. [MEDIUM:70] Version extraction lacks robustness

    • Line 36: Sed regex uses greedy matching (`.*") which could backtrack excessively on malformed Cargo.toml
    • No validation that the extraction succeeded before using the result in comparisons
    • Should add explicit validation or use more precise regex

    VERSION=$(grep '^version' Cargo.toml | head -1 | sed 's/.*"\(.*\)"/\1/')
    echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
    echo "Detected version: ${VERSION}"

  6. [LOW:70] Unnecessary broad permissions

    • Line 23: actions: write permission is not used and should be removed
    • Workflow only needs contents: read (checkout) and packages: read (Docker operations)
    • Reduces attack surface by principle of least privilege

    runs-on: ubuntu-24.04
    permissions:
    actions: write
    contents: read
    packages: read

  7. [LOW:60] Missing timeout on docker build-push

    • Line 78: docker/build-push-action has no explicit timeout specification
    • Falls back to 6-hour GitHub Actions default, leading to wasted CI time on hung jobs
    • Recommend adding a 30-minute timeout for faster failure feedback

    - name: Build and push
    uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
    with:
    context: .
    push: true
    tags: ${{ env.IMAGE_NAME }}:${{ inputs.tag }}
    target: runtime
    platforms: linux/amd64
    cache-from: type=gha
    cache-to: type=gha,mode=max

Base automatically changed from staging-promote/427783da-24468358894 to main April 18, 2026 00:59
@henrypark133
henrypark133 merged commit b3478cf into main Apr 18, 2026
39 of 48 checks passed
@henrypark133
henrypark133 deleted the staging-promote/b3478cf3-24481112105 branch April 18, 2026 01:00

This branch had an error being deployed

1 failed and 5 inactive deployments
Ironclaw-QA / production — b3478cf3 Deployed Apr 15, 2026 by railway-app[bot]
ironclaw-nearai / production — b3478cf3 Deployed Apr 15, 2026 by railway-app[bot]
venice-ironclaw / production — b3478cf3 Deployed Apr 15, 2026 by railway-app[bot]
cosmose-ironclaw / production — b3478cf3 Deployed Apr 15, 2026 by railway-app[bot]
humble-cat / staging-cameron — b3478cf3 Deployed Apr 15, 2026 by railway-app[bot]
Near Foundation Ironclaw / production — b3478cf3 Deployed Apr 15, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows size: M 50-199 changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant