Skip to content

fix: support verified existing GHCR image deployments - #37

Merged
sprahasingh merged 1 commit into
mainfrom
fix/deploy-existing-ghcr-image
Oct 9, 2026
Merged

sprahasingh merged 1 commit into
mainfrom
fix/deploy-existing-ghcr-image

Conversation

@sprahasingh

Copy link
Copy Markdown
Owner

No description provided.

@codelens-gh

codelens-gh Bot commented Oct 9, 2026

Copy link
Copy Markdown

CodeLens Pre-Review Analysis

Outcome: Incomplete; an external service prevented full analysis

9 hunks scanned · 20 similar past patterns matched

Historically grounded findings

Suggested checks from historical patterns

These are speculative checks, not asserted defects.


Finding 1: The workflow uses an unpinned GitHub Action reference (actions/checkout@v7.0.1) which may violate the repository’s policy requiring actions to be pinned to a commit SHA

Location: .github/workflows/production.yml · line 38
Model confidence (uncalibrated): 90% | What to verify: Pin the checkout action to a specific commit SHA or use a hash instead of the version tag

Your code (this PR):

    if: github.event_name != 'workflow_dispatch' || inputs.operation == 'deploy' || inputs.operation == 'deploy_existing'

Evidence: Past reviewers flagged similar unpinned action references in other workflow files (comments [0] and [1])

Past reviews that triggered this (2 matches):

Similarity Source repository File Reviewer comment Link
83% tiangolo/fastapi .github/workflows/run-tests.yml "## zizmor / unpinned action reference: action is not pinned to a hash (required by blank..." view
83% tiangolo/fastapi .github/workflows/run-tests.yml "## zizmor / unpinned action reference: action is not pinned to a hash (required by blank..." view

Finding 2: GitHub Actions steps use action references that are not pinned to a commit SHA (e.g., actions/checkout@v7.0.1)

Location: .github/workflows/production.yml · line 9
Model confidence (uncalibrated): 90% | What to verify: Pin the action to a specific commit SHA instead of a tag or version alias

Your code (this PR):

        options: [deploy, deploy_existing, rollback]
      publication_run_id:
        description: Successful main publication run for deploy_existing
        type: string
        required: false
      source_commit:
        description: Full source commit SHA for deploy_existing
        type: string
... (5 more lines)

Evidence: Past review comment flagged unpinned action references as a security policy violation

Past reviews that triggered this (1 match):

Similarity Source repository File Reviewer comment Link
74% tiangolo/fastapi .github/workflows/run-tests.yml "## zizmor / unpinned action reference: action is not pinned to a hash (required by blank..." view

Suggested check 3: The workflow uses an action reference (actions/checkout@v7.0.1) that is not pinned to a specific commit SHA, which violates the repository’s pin‑to‑hash policy

Location: .github/workflows/production.yml · line 95
Model confidence (uncalibrated): 90% | What to verify: Replace the tag‑based reference with a SHA‑pinned reference (e.g., actions/checkout@<commit‑sha>) or ensure the policy allows tag pins

Your code (this PR):

          --volume "$GITHUB_WORKSPACE/.github/workflows/production.yml:/tmp/production.yml:ro"
          --env CODELENS_WORKFLOW_FILE=/tmp/production.yml
          --env PYTHONPATH=/tmp

Evidence: Past reviewers flagged similar unpinned action references in other workflow files (comments 3 and 4)

Past reviews that triggered this (2 matches):

Similarity Source repository File Reviewer comment Link
82% tiangolo/fastapi .github/workflows/run-tests.yml "## zizmor / unpinned action reference: action is not pinned to a hash (required by blank..." view
81% tiangolo/fastapi .github/workflows/run-tests.yml "## zizmor / unpinned action reference: action is not pinned to a hash (required by blank..." view

Generated by CodeLens. Historically grounded findings cite their source reviews; general analysis is labeled separately.

General change overview (not historical evidence)

Changed areas (4 files; +586/-14 lines):

  • .github/workflows/production.yml (+58/-8)
  • docs/ghcr-deployment.md (+28/-6)
  • scripts/verify_ghcr_publication.py (+248/-0)
  • tests/test_verify_ghcr_publication.py (+252/-0)
    Test files changed: tests/test_verify_ghcr_publication.py

Analysis status: Groq synthesis failed after its bounded retries. This review is incomplete; no no-findings conclusion was reached.

Note: This analysis is partial. Review the analysis status above for the reason and the scope that was not completed.

@sprahasingh
sprahasingh merged commit 46734dd into main Oct 9, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant