Skip to content

fix(workflows): resolve 12 CI/CD bugs across 12 workflow files - #981

Merged
Smartdevs17 merged 2 commits into
Smartdevs17:mainfrom
Masked18:fix/workflow-audit-fixes
Sep 28, 2026
Merged

Smartdevs17 merged 2 commits into
Smartdevs17:mainfrom
Masked18:fix/workflow-audit-fixes

Conversation

@Masked18

Copy link
Copy Markdown

Summary

Full audit of all 29 GitHub Actions workflow files. Found and fixed 12 distinct bugs across 12 files.


Changes

backup.yml

  • Upgraded slackapi/slack-github-action from deprecated v1.24.0 to v2.1.0
  • Added required webhook-type: incoming-webhook field (mandatory in v2+)

bundle-size.yml

  • Added cache-dependency-path: frontend/package-lock.json to setup-node to prevent stale cache key collisions

canary.yml

  • Added needs: [canary-10, canary-50, production-rollout] to the rollback job — without it if: failure() can never observe upstream job failures

coverage.yml

  • Fixed Codecov directory path: frontend/coverage → coverage (the step already runs under working-directory: frontend, so the absolute path was wrong)
  • Added cache-dependency-path: frontend/package-lock.json to setup-node

fuzz-testing.yml

  • Fixed Rust component name: llvm-tools-preview → llvm-tools (the preview component was renamed and no longer exists)
  • Downgraded codecov/codecov-action from v5 → v4 for consistency with every other workflow in the repo

performance.yml

  • Removed the npx next export step — next export was removed in Next.js 14 and caused silent failures (the step had continue-on-error: true masking the breakage); replaced with next start
  • Fixed the Block PR on budget exceeded step: the if: expression steps.bundle-check.outputs.js_size > 500 does a string comparison in GitHub Actions (always false for numbers), not an integer comparison — moved the guard into the shell script using [ "${JS_SIZE}" -gt 500 ]

performance-monitoring.yml

  • Fixed npm run build missing working-directory: frontend — the root workspace has no build script so this always failed
  • Upgraded @lhci/cli from 0.11.x → 0.14.x to match performance.yml

release.yml

  • Added cache: 'npm' and cache-dependency-path: package-lock.json to the setup-node step — it was the only workflow that didn't cache dependencies, causing slow cold-starts on every release

sdk-generation.yml

  • Fixed wrong npm package: @openapi-diff/openapi-diff does not install the oasdiff binary — replaced with @oasdiff/oasdiff which is the correct package

security-audit-pipeline.yml

  • Removed unused services block (node:20-alpine container) from the dast job — the backend was being installed directly on the runner anyway, making the service container a wasted resource that also competed for port 3001

security-audit.yml

  • Fixed broken Slither CLI flags: --risk high,medium and --output-to-file {severity}-{type}-slither-report.md are not valid Slither arguments — replaced with --checklist --markdown-root . which generates the correct human-readable output
  • Fixed uninitialized variable bug in the Mythril job: the accumulator was named CRITICAL but the threshold check tested CRITICAL_COUNT — CRITICAL was never initialized so $((CRITICAL + ...)) always evaluated to the jq output alone, and CRITICAL_COUNT remained 0, meaning critical findings were silently swallowed

autoscaling.yml

  • Added missing workflow_dispatch.inputs block for scale_profile, min_parallel, and max_parallel — these inputs were referenced in job steps (${{ inputs.scale_profile }} etc.) but never declared, causing GitHub Actions to substitute empty strings and always fall through to the balanced default unintentionally

Files changed

autoscaling.yml, backup.yml, bundle-size.yml, canary.yml, coverage.yml, fuzz-testing.yml, performance-monitoring.yml, performance.yml, release.yml, sdk-generation.yml, security-audit-pipeline.yml, security-audit.yml

@vercel

vercel Bot commented Sep 27, 2026

Copy link
Copy Markdown

@Masked18 is attempting to deploy a commit to the smartdevs17's projects Team on Vercel.

A member of the Team first needs to authorize it.

@Smartdevs17
Smartdevs17 merged commit 60a6ce1 into Smartdevs17:main Sep 28, 2026
1 check passed
@gitguardian

gitguardian Bot commented Sep 28, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 2 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
37573581 Triggered Zapier Webhook URL fee4f97 backend/docs/ZAPIER_INTEGRATION.md View secret
15742864 Triggered Generic Password fee4f97 .github/workflows/backup.yml View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants