Repository navigation
fix(release): gate kics release workflows behind release environment - #8108
Merged
Merged
Conversation
The release workflows deployed without declaring the `release` environment, so the Docker Hub OIDC connection ID (an environment secret) resolved empty and the registry login never actually authenticated. Adding `environment: release` to each job fixes that and applies the existing approval/master-only deployment policy. Since release-event runs execute on a tag ref, which the environment's master-only policy would reject, the `release:` and `push:` triggers are replaced with manual dispatch. The now-dead prerelease `if:` checks are removed, and the Docker Hub username is read from the environment variable instead of being hardcoded. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Repoints the default CODEOWNERS entry from @Checkmarx/kics to @Checkmarx/cx-maintainers-kics so it aligns with the reviewer team enforced by the kics repo's merge-protection ruleset. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cx-artur-ribeiro
approved these changes
Sep 7, 2026
cx-alon-rosenhek
approved these changes
Sep 9, 2026
cx-bruno-silva
approved these changes
Sep 9, 2026
cx-rui-araujo
approved these changes
Sep 9, 2026
Contributor
✅ No secrets detectedTruffleHog found no secrets in the current commits of this PR. |
social4hyq
pushed a commit
to social4hyq/homebrew-core
that referenced
this pull request
Sep 20, 2026
kics 2.2.0 Created-by: HarmonybrewBot Commit-by: HarmonybrewBot Merged-by: HarmonybrewBot Description: Created by `brew bump` --- Created with `brew bump-formula-pr`.<details> <summary>release notes</summary> <pre>## What's Changed * docs(release): update queries catalog, index and dockerfile for upcoming release by @cx-artur-ribeiro in Checkmarx/kics#8094 * fix(query): added missing case to "Last User is Root" Dockerfile query. by @cx-andre-pereira in Checkmarx/kics#8095 * feat(queries): new queries to check if synapse workspace managed virtual network is enabled by @cx-ricardo-jesus in Checkmarx/kics#8097 * refactor(descriptions): remove pkg/descriptions and related CLI flag by @cx-ricardo-jesus in Checkmarx/kics#8092 * CISO-1264 - Update GitHub Actions runner labels by @cx-jonathan-hartman in Checkmarx/kics#8093 * fix(query): Fix for Missing Backslash Support on Copy_With_More_Than_Two_Arguments_Not_Ending_With_Slash query by @cx-andre-pereira in Checkmarx/kics#8099 * fix(actions): refactor gh actions to fix CI by @cx-artur-ribeiro in Checkmarx/kics#8098 * fix(query): change to keyExpectedValue on ARM 'default_azure_storage_account_network_access_is_too_permissive' query by @cx-andre-pereira in Checkmarx/kics#8101 * update(version): rename VERSION build-arg to ENGINE_VERSION by @cx-artur-ribeiro in Checkmarx/kics#8102 * fix(query): correct keyExpectedValue and keyActualValue in redshift_not_encrypted by @cx-ricardo-jesus in Checkmarx/kics#8105 * fix(analyzer): bound file analysis workers by @omribz156 in Checkmarx/kics#8058 * fix(actions): remove outdated actions and update documentation accordingly by @cx-artur-ribeiro in Checkmarx/kics#8110 * fix(action): remove concurrent group from run projects github action by @cx-artur-ribeiro in Checkmarx/kics#8111 * fix(test): normalize timestamp comparison in TestInitCycloneDxReport by @cx-artur-ribeiro in Checkmarx/kics#8113 * fix(actions): fix security vulnerabilities and update ci with new enforced rules by @cx-artur-ribeiro in Checkmarx/kics#8118 * fix(release): gate kics release workflows behind release environment by @cx-lior-poterman in Checkmarx/kics#8108 * fix(validator): update queries validator for cwe and risk score fields by @cx-artur-ribeiro in Checkmarx/kics#8028 * fix(version): new available version with additional v prefix by @cx-artur-ribeiro in Checkmarx/kics#8119 * fix(analyzer): improvement to dockerfile scanning by @cx-andre-pereira in Checkmarx/kics#8114 * chore(release): removed unused goreleaser configuration files by @cx-ricardo-jesus in Checkmarx/kics#8122 * fix(filesystem): skip cache files by extension by @cx-laura-rodrigues in Checkmarx/kics#8112 * fix(query): changed all dockerfile queries for case insensitive support of dockerfile commands by @cx-andre-pereira in Checkmarx/kics#8115 * docs(release): update queries catalog, index and dockerfile for 2.2.0 by @cx-artur-ribeiro in Checkmarx/kics#8126 ## New Contributors * @cx-jonathan-hartman made their first contribution in Checkmarx/kics#8093 * @omribz156 made their first contribution in Checkmarx/kics#8058 * @cx-lior-poterman made their first contribution in Checkmarx/kics#8108 **Full Changelog**: https://github.com/Checkmarx/kics/compare/v2.1.21...v2.2.0</pre> <p>View the full release notes at <a href="https://github.com/Checkmarx/kics/releases/tag/v2.2.0">https://github.com/Checkmarx/kics/releases/tag/v2.2.0</a>.</p> </details> <hr> See merge request: Harmonybrew/homebrew-core!20473
cx-andre-pereira
pushed a commit
that referenced
this pull request
Sep 29, 2026
…8108) * fix(ci): gate kics release workflows behind release environment The release workflows deployed without declaring the `release` environment, so the Docker Hub OIDC connection ID (an environment secret) resolved empty and the registry login never actually authenticated. Adding `environment: release` to each job fixes that and applies the existing approval/master-only deployment policy. Since release-event runs execute on a tag ref, which the environment's master-only policy would reject, the `release:` and `push:` triggers are replaced with manual dispatch. The now-dead prerelease `if:` checks are removed, and the Docker Hub username is read from the environment variable instead of being hardcoded. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(codeowners): point default ownership at cx-maintainers-kics Repoints the default CODEOWNERS entry from @checkmarx/kics to @Checkmarx/cx-maintainers-kics so it aligns with the reviewer team enforced by the kics repo's merge-protection ruleset. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * empty commit --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cx-andre-pereira
pushed a commit
that referenced
this pull request
Sep 29, 2026
…8108) * fix(ci): gate kics release workflows behind release environment The release workflows deployed without declaring the `release` environment, so the Docker Hub OIDC connection ID (an environment secret) resolved empty and the registry login never actually authenticated. Adding `environment: release` to each job fixes that and applies the existing approval/master-only deployment policy. Since release-event runs execute on a tag ref, which the environment's master-only policy would reject, the `release:` and `push:` triggers are replaced with manual dispatch. The now-dead prerelease `if:` checks are removed, and the Docker Hub username is read from the environment variable instead of being hardcoded. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(codeowners): point default ownership at cx-maintainers-kics Repoints the default CODEOWNERS entry from @checkmarx/kics to @Checkmarx/cx-maintainers-kics so it aligns with the reviewer team enforced by the kics repo's merge-protection ruleset. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * empty commit --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes the four release workflows (prepare-release, release-dkr-image, update-docs-queries, update-docs-release) manual-dispatch-only and gates them behind the
releaseenvironment. This fixes the Docker Hub OIDC connection id resolving empty, since it's stored as an environment secret that only the gated environment can see.Also repoints
.github/CODEOWNERSfrom@checkmarx/kicsto@Checkmarx/cx-maintainers-kicsto match the reviewer team enforced by the merge-protection ruleset.I submit this contribution under the Apache-2.0 license.