From 524f25aa45cfaa905da7045330a79d360d465be0 Mon Sep 17 00:00:00 2001 From: Lior Poterman <191881919+cx-lior-poterman@users.noreply.github.com> Date: Mon, 7 Sep 2026 12:04:11 +0300 Subject: [PATCH 1/3] fix(ci): gate kics release workflows behind release environment The release workflows deployed without declaring the `release` environment, so the Docker Hub OIDC connection ID (an environment secret) resolved empty and the registry login never actually authenticated. Adding `environment: release` to each job fixes that and applies the existing approval/master-only deployment policy. Since release-event runs execute on a tag ref, which the environment's master-only policy would reject, the `release:` and `push:` triggers are replaced with manual dispatch. The now-dead prerelease `if:` checks are removed, and the Docker Hub username is read from the environment variable instead of being hardcoded. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/prepare-release.yaml | 1 + .github/workflows/release-dkr-image.yml | 6 ++---- .github/workflows/update-docs-queries.yaml | 7 +------ .github/workflows/update-docs-release.yaml | 4 +--- 4 files changed, 5 insertions(+), 13 deletions(-) diff --git a/.github/workflows/prepare-release.yaml b/.github/workflows/prepare-release.yaml index 47e743936bb..bf346ee2de4 100644 --- a/.github/workflows/prepare-release.yaml +++ b/.github/workflows/prepare-release.yaml @@ -15,6 +15,7 @@ concurrency: jobs: prepare-release: name: prepare for next release + environment: release runs-on: cx-public-ubuntu-x64 permissions: contents: write # for actions/checkout to fetch code and create-pull-request to push a branch diff --git a/.github/workflows/release-dkr-image.yml b/.github/workflows/release-dkr-image.yml index a7890ca8ecc..0becf2faf86 100644 --- a/.github/workflows/release-dkr-image.yml +++ b/.github/workflows/release-dkr-image.yml @@ -1,8 +1,6 @@ name: release-docker-image on: - release: - types: [created, published] workflow_dispatch: concurrency: @@ -15,8 +13,8 @@ permissions: jobs: push_to_registry: name: Push Docker image to Docker Hub + environment: release runs-on: cx-public-ubuntu-x64 - if: "!github.event.release.prerelease" permissions: contents: read id-token: write # required to request the GitHub OIDC token exchanged with Docker Hub's OIDC login @@ -56,7 +54,7 @@ jobs: - name: Login to DockerHub uses: step-security/docker-login-action@bd6978fd4ef9a5f78130095b298b8a721afcb0d8 # v4.5.1 with: - username: checkmarx + username: ${{ vars.DOCKERHUB_USERNAME }} env: DOCKERHUB_OIDC_CONNECTIONID: ${{ secrets.DOCKERHUB_OIDC_CONNECTIONID }} - name: Get current date diff --git a/.github/workflows/update-docs-queries.yaml b/.github/workflows/update-docs-queries.yaml index 96282b058c8..bb39ba57294 100644 --- a/.github/workflows/update-docs-queries.yaml +++ b/.github/workflows/update-docs-queries.yaml @@ -2,12 +2,6 @@ name: update-queries-docs on: workflow_dispatch: - push: - branches: [master] - paths: - - "assets/queries/**/metadata.json" - - "assets/queries/**/test/**" - - ".github/scripts/docs-generator/**" permissions: contents: read @@ -19,6 +13,7 @@ concurrency: jobs: update-docs: name: Update queries documentation + environment: release permissions: actions: write # for styfle/cancel-workflow-action to cancel/stop running workflows contents: write # for actions/checkout to fetch code and create-pull-request to push a branch diff --git a/.github/workflows/update-docs-release.yaml b/.github/workflows/update-docs-release.yaml index ed262cea10f..cd25af44952 100644 --- a/.github/workflows/update-docs-release.yaml +++ b/.github/workflows/update-docs-release.yaml @@ -2,8 +2,6 @@ name: update-docs-release on: workflow_dispatch: - release: - type: [published] permissions: contents: read @@ -15,11 +13,11 @@ concurrency: jobs: update-docs-release: name: Create new docs version + environment: release permissions: actions: write # for styfle/cancel-workflow-action to cancel/stop running workflows contents: write # for Git to git push runs-on: cx-public-ubuntu-x64 - if: "!github.event.release.prerelease" steps: - name: Cancel Previous Runs uses: styfle/cancel-workflow-action@85880fa0301c86cca9da44039ee3bb12d3bedbfa # 0.12.1 From 2ab02090b54b86642c33ca9f0c4a37e18b311f28 Mon Sep 17 00:00:00 2001 From: Lior Poterman <191881919+cx-lior-poterman@users.noreply.github.com> Date: Mon, 7 Sep 2026 12:37:17 +0300 Subject: [PATCH 2/3] chore(codeowners): point default ownership at cx-maintainers-kics Repoints the default CODEOWNERS entry from @checkmarx/kics to @Checkmarx/cx-maintainers-kics so it aligns with the reviewer team enforced by the kics repo's merge-protection ruleset. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/CODEOWNERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index bb0769c8b38..a33cbd65161 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1 +1 @@ -* @checkmarx/kics +* @Checkmarx/cx-maintainers-kics From e4c6546280bf427471745f0ba3bf1261d7cd7362 Mon Sep 17 00:00:00 2001 From: Lior Poterman <191881919+cx-lior-poterman@users.noreply.github.com> Date: Wed, 9 Sep 2026 13:59:53 +0300 Subject: [PATCH 3/3] empty commit