fix(workflows): resolve 12 CI/CD bugs across 12 workflow files - #981
Conversation
|
@Masked18 is attempting to deploy a commit to the smartdevs17's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 37573581 | Triggered | Zapier Webhook URL | fee4f97 | backend/docs/ZAPIER_INTEGRATION.md | View secret |
| 15742864 | Triggered | Generic Password | fee4f97 | .github/workflows/backup.yml | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secrets safely. Learn here the best practices.
- Revoke and rotate these secrets.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
Summary
Full audit of all 29 GitHub Actions workflow files. Found and fixed 12 distinct bugs across 12 files.
Changes
backup.ymlslackapi/slack-github-actionfrom deprecatedv1.24.0tov2.1.0webhook-type: incoming-webhookfield (mandatory in v2+)bundle-size.ymlcache-dependency-path: frontend/package-lock.jsontosetup-nodeto prevent stale cache key collisionscanary.ymlneeds: [canary-10, canary-50, production-rollout]to therollbackjob — without itif: failure()can never observe upstream job failurescoverage.ymldirectorypath:frontend/coverage→coverage(the step already runs underworking-directory: frontend, so the absolute path was wrong)cache-dependency-path: frontend/package-lock.jsontosetup-nodefuzz-testing.ymlllvm-tools-preview→llvm-tools(the preview component was renamed and no longer exists)codecov/codecov-actionfromv5→v4for consistency with every other workflow in the repoperformance.ymlnpx next exportstep —next exportwas removed in Next.js 14 and caused silent failures (the step hadcontinue-on-error: truemasking the breakage); replaced withnext startBlock PR on budget exceededstep: theif:expressionsteps.bundle-check.outputs.js_size > 500does a string comparison in GitHub Actions (always false for numbers), not an integer comparison — moved the guard into the shell script using[ "${JS_SIZE}" -gt 500 ]performance-monitoring.ymlnpm run buildmissingworking-directory: frontend— the root workspace has nobuildscript so this always failed@lhci/clifrom0.11.x→0.14.xto matchperformance.ymlrelease.ymlcache: 'npm'andcache-dependency-path: package-lock.jsonto thesetup-nodestep — it was the only workflow that didn't cache dependencies, causing slow cold-starts on every releasesdk-generation.yml@openapi-diff/openapi-diffdoes not install theoasdiffbinary — replaced with@oasdiff/oasdiffwhich is the correct packagesecurity-audit-pipeline.ymlservicesblock (node:20-alpinecontainer) from thedastjob — the backend was being installed directly on the runner anyway, making the service container a wasted resource that also competed for port 3001security-audit.yml--risk high,mediumand--output-to-file {severity}-{type}-slither-report.mdare not valid Slither arguments — replaced with--checklist --markdown-root .which generates the correct human-readable outputCRITICALbut the threshold check testedCRITICAL_COUNT—CRITICALwas never initialized so$((CRITICAL + ...))always evaluated to the jq output alone, andCRITICAL_COUNTremained 0, meaning critical findings were silently swallowedautoscaling.ymlworkflow_dispatch.inputsblock forscale_profile,min_parallel, andmax_parallel— these inputs were referenced in job steps (${{ inputs.scale_profile }}etc.) but never declared, causing GitHub Actions to substitute empty strings and always fall through to thebalanceddefault unintentionallyFiles changed
autoscaling.yml,backup.yml,bundle-size.yml,canary.yml,coverage.yml,fuzz-testing.yml,performance-monitoring.yml,performance.yml,release.yml,sdk-generation.yml,security-audit-pipeline.yml,security-audit.yml