From b5f617eb100cc811d7624c66761f43a787dd0027 Mon Sep 17 00:00:00 2001 From: Or Balayla Date: Tue, 22 Sep 2026 16:47:27 +0300 Subject: [PATCH 1/3] ci: trigger the release scan on GitHub release The release scan pipeline had no trigger, so it was started by hand from Jenkins for every release. Forward the release event to its webhook instead, and fire on pre-releases too so release candidates are scanned before anything ships. Runs on a self-hosted runner because the Jenkins instance is not reachable from GitHub-hosted runners. Refs: HPCINFRA-4859 Signed-off-by: Or Balayla --- .github/workflows/release-scan.yml | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 .github/workflows/release-scan.yml diff --git a/.github/workflows/release-scan.yml b/.github/workflows/release-scan.yml new file mode 100644 index 000000000..97a64a4af --- /dev/null +++ b/.github/workflows/release-scan.yml @@ -0,0 +1,29 @@ +# Triggers the CloudAI release scan when a GitHub release is published. Fires on +# pre-releases too, so release candidates are scanned before anything ships. +name: Release scan + +on: + release: + types: [published, prereleased] + +jobs: + trigger: + name: Trigger release scan + # Jenkins is not reachable from GitHub-hosted runners. + runs-on: blossom + + steps: + - name: Trigger release scan + env: + RELEASE_CI_SERVER: ${{ secrets.RELEASE_CI_SERVER }} + PAYLOAD: ${{ toJSON(github.event) }} + # Via env, not interpolated: a tag name is attacker-controlled text. + RELEASE_TAG: ${{ github.event.release.tag_name }} + run: | + set -eu + curl --fail --silent --show-error \ + --connect-timeout 15 --max-time 60 \ + -X POST "${RELEASE_CI_SERVER}" \ + -H 'Content-Type: application/json' \ + --data-raw "${PAYLOAD}" + echo "Release scan triggered for ${RELEASE_TAG}" From e2921af268e79283f8fd68875640b0de37427fc6 Mon Sep 17 00:00:00 2001 From: Or Balayla Date: Mon, 28 Sep 2026 16:15:06 +0300 Subject: [PATCH 2/3] TEMP DO NOT MERGE: drop the Python pin so the Blossom scan can run The Blossom scanner image resolves python through pyenv with its working directory inside our checkout, so it reads .python-version, asks for 3.14 and exits before scanning. Removing the file for the duration of this PR lets the scan run so the rest of the pipeline can be verified. Revert this commit before merge. Tracked on HPCINFRA-4862. Signed-off-by: Or Balayla --- .github/workflows/ci.yml | 2 +- .python-version | 1 - 2 files changed, 1 insertion(+), 2 deletions(-) delete mode 100644 .python-version diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f452349c1..31d47087d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -17,7 +17,7 @@ jobs: - name: Set up Python uses: actions/setup-python@v6 with: - python-version-file: .python-version + python-version: "3.14" - name: Install uv uses: astral-sh/setup-uv@v5 diff --git a/.python-version b/.python-version deleted file mode 100644 index 6324d401a..000000000 --- a/.python-version +++ /dev/null @@ -1 +0,0 @@ -3.14 From 591cc6c234298dc33d87f09fb7a1d7f4e86495f0 Mon Sep 17 00:00:00 2001 From: Or Balayla Date: Mon, 28 Sep 2026 16:41:38 +0300 Subject: [PATCH 3/3] ci: drop the redundant prereleased trigger and require https published already fires for pre-releases, so listening for both sent two webhook requests for one pre-release. The webhook URL carries the trigger token, so reject a non-https RELEASE_CI_SERVER and restrict curl to https. Signed-off-by: Or Balayla --- .github/workflows/release-scan.yml | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/.github/workflows/release-scan.yml b/.github/workflows/release-scan.yml index 97a64a4af..c495758ab 100644 --- a/.github/workflows/release-scan.yml +++ b/.github/workflows/release-scan.yml @@ -1,10 +1,10 @@ -# Triggers the CloudAI release scan when a GitHub release is published. Fires on -# pre-releases too, so release candidates are scanned before anything ships. +# Triggers the CloudAI release scan when a GitHub release is published. +# published also fires for pre-releases, so release candidates are covered. name: Release scan on: release: - types: [published, prereleased] + types: [published] jobs: trigger: @@ -21,7 +21,14 @@ jobs: RELEASE_TAG: ${{ github.event.release.tag_name }} run: | set -eu - curl --fail --silent --show-error \ + + # The URL carries the trigger token, so refuse to send it in clear. + case "${RELEASE_CI_SERVER}" in + https://*) ;; + *) echo "RELEASE_CI_SERVER must be an https URL" >&2; exit 1 ;; + esac + + curl --fail --silent --show-error --proto '=https' \ --connect-timeout 15 --max-time 60 \ -X POST "${RELEASE_CI_SERVER}" \ -H 'Content-Type: application/json' \