Skip to content

fix(release): gate kics release workflows behind release environment - #8108

Merged
cx-artur-ribeiro merged 5 commits into
masterfrom
ast-171789-kics-release-env-gate
Sep 10, 2026
Merged

cx-artur-ribeiro merged 5 commits into
masterfrom
ast-171789-kics-release-env-gate

Conversation

@cx-lior-poterman

@cx-lior-poterman cx-lior-poterman commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Makes the four release workflows (prepare-release, release-dkr-image, update-docs-queries, update-docs-release) manual-dispatch-only and gates them behind the release environment. This fixes the Docker Hub OIDC connection id resolving empty, since it's stored as an environment secret that only the gated environment can see.

Also repoints .github/CODEOWNERS from @checkmarx/kics to @Checkmarx/cx-maintainers-kics to match the reviewer team enforced by the merge-protection ruleset.

I submit this contribution under the Apache-2.0 license.

cx-lior-poterman and others added 2 commits September 7, 2026 12:04
The release workflows deployed without declaring the `release`
environment, so the Docker Hub OIDC connection ID (an environment
secret) resolved empty and the registry login never actually
authenticated. Adding `environment: release` to each job fixes that
and applies the existing approval/master-only deployment policy.

Since release-event runs execute on a tag ref, which the
environment's master-only policy would reject, the `release:` and
`push:` triggers are replaced with manual dispatch. The now-dead
prerelease `if:` checks are removed, and the Docker Hub username is
read from the environment variable instead of being hardcoded.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Repoints the default CODEOWNERS entry from @Checkmarx/kics to
@Checkmarx/cx-maintainers-kics so it aligns with the reviewer team
enforced by the kics repo's merge-protection ruleset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@cx-lior-poterman cx-lior-poterman changed the title AST-171789 Gate kics release workflows behind release environment fix(release): Gate kics release workflows behind release environment Sep 9, 2026
@cx-artur-ribeiro cx-artur-ribeiro changed the title fix(release): Gate kics release workflows behind release environment fix(release): gate kics release workflows behind release environment Sep 9, 2026
@cx-lior-poterman
cx-lior-poterman requested a review from a team September 9, 2026 10:59
@github-actions

github-actions Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ No secrets detected

TruffleHog found no secrets in the current commits of this PR.

@cx-artur-ribeiro
cx-artur-ribeiro merged commit d28435b into master Sep 10, 2026
38 of 41 checks passed
@cx-artur-ribeiro
cx-artur-ribeiro deleted the ast-171789-kics-release-env-gate branch September 10, 2026 14:57
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
kics 2.2.0

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre>## What's Changed
* docs(release): update queries catalog, index and dockerfile for upcoming release by @cx-artur-ribeiro in Checkmarx/kics#8094
* fix(query): added missing case to "Last User is Root" Dockerfile query. by @cx-andre-pereira in Checkmarx/kics#8095
* feat(queries): new queries to check if synapse workspace managed virtual network is enabled by @cx-ricardo-jesus in Checkmarx/kics#8097
* refactor(descriptions): remove pkg/descriptions and related CLI flag by @cx-ricardo-jesus in Checkmarx/kics#8092
* CISO-1264 - Update GitHub Actions runner labels by @cx-jonathan-hartman in Checkmarx/kics#8093
* fix(query): Fix for Missing Backslash Support on Copy_With_More_Than_Two_Arguments_Not_Ending_With_Slash query by @cx-andre-pereira in Checkmarx/kics#8099
* fix(actions): refactor gh actions to fix CI by @cx-artur-ribeiro in Checkmarx/kics#8098
* fix(query): change to keyExpectedValue on ARM 'default_azure_storage_account_network_access_is_too_permissive' query by @cx-andre-pereira in Checkmarx/kics#8101
* update(version): rename VERSION build-arg to ENGINE_VERSION by @cx-artur-ribeiro in Checkmarx/kics#8102
* fix(query): correct keyExpectedValue and keyActualValue in redshift_not_encrypted by @cx-ricardo-jesus in Checkmarx/kics#8105
* fix(analyzer): bound file analysis workers by @omribz156 in Checkmarx/kics#8058
* fix(actions): remove outdated actions and update documentation accordingly by @cx-artur-ribeiro in Checkmarx/kics#8110
* fix(action): remove concurrent group from run projects github action by @cx-artur-ribeiro in Checkmarx/kics#8111
* fix(test): normalize timestamp comparison in TestInitCycloneDxReport by @cx-artur-ribeiro in Checkmarx/kics#8113
* fix(actions): fix security vulnerabilities and update ci with new enforced rules by @cx-artur-ribeiro in Checkmarx/kics#8118
* fix(release): gate kics release workflows behind release environment by @cx-lior-poterman in Checkmarx/kics#8108
* fix(validator): update queries validator for cwe and risk score fields by @cx-artur-ribeiro in Checkmarx/kics#8028
* fix(version): new available version with additional v prefix by @cx-artur-ribeiro in Checkmarx/kics#8119
* fix(analyzer): improvement to dockerfile scanning by @cx-andre-pereira in Checkmarx/kics#8114
* chore(release): removed unused goreleaser configuration files by @cx-ricardo-jesus in Checkmarx/kics#8122
* fix(filesystem): skip cache files by extension by @cx-laura-rodrigues in Checkmarx/kics#8112
* fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands by @cx-andre-pereira in Checkmarx/kics#8115
* docs(release): update queries catalog, index and dockerfile for 2.2.0 by @cx-artur-ribeiro in Checkmarx/kics#8126

## New Contributors
* @cx-jonathan-hartman made their first contribution in Checkmarx/kics#8093
* @omribz156 made their first contribution in Checkmarx/kics#8058
* @cx-lior-poterman made their first contribution in Checkmarx/kics#8108

**Full Changelog**: https://github.com/Checkmarx/kics/compare/v2.1.21...v2.2.0</pre>
  <p>View the full release notes at <a href="https://github.com/Checkmarx/kics/releases/tag/v2.2.0">https://github.com/Checkmarx/kics/releases/tag/v2.2.0</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!20473
cx-andre-pereira pushed a commit that referenced this pull request Sep 29, 2026
…8108)

* fix(ci): gate kics release workflows behind release environment

The release workflows deployed without declaring the `release`
environment, so the Docker Hub OIDC connection ID (an environment
secret) resolved empty and the registry login never actually
authenticated. Adding `environment: release` to each job fixes that
and applies the existing approval/master-only deployment policy.

Since release-event runs execute on a tag ref, which the
environment's master-only policy would reject, the `release:` and
`push:` triggers are replaced with manual dispatch. The now-dead
prerelease `if:` checks are removed, and the Docker Hub username is
read from the environment variable instead of being hardcoded.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(codeowners): point default ownership at cx-maintainers-kics

Repoints the default CODEOWNERS entry from @checkmarx/kics to
@Checkmarx/cx-maintainers-kics so it aligns with the reviewer team
enforced by the kics repo's merge-protection ruleset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* empty commit

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cx-andre-pereira pushed a commit that referenced this pull request Sep 29, 2026
…8108)

* fix(ci): gate kics release workflows behind release environment

The release workflows deployed without declaring the `release`
environment, so the Docker Hub OIDC connection ID (an environment
secret) resolved empty and the registry login never actually
authenticated. Adding `environment: release` to each job fixes that
and applies the existing approval/master-only deployment policy.

Since release-event runs execute on a tag ref, which the
environment's master-only policy would reject, the `release:` and
`push:` triggers are replaced with manual dispatch. The now-dead
prerelease `if:` checks are removed, and the Docker Hub username is
read from the environment variable instead of being hardcoded.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(codeowners): point default ownership at cx-maintainers-kics

Repoints the default CODEOWNERS entry from @checkmarx/kics to
@Checkmarx/cx-maintainers-kics so it aligns with the reviewer team
enforced by the kics repo's merge-protection ruleset.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* empty commit

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants