github-advanced-security[bot] commented on code in PR #74173:
URL: https://github.com/apache/airflow/pull/74173#discussion_r4176192808
##########
.github/workflows/ci-image-build.yml:
##########
@@ -401,3 +401,58 @@
steps.stashed-image.outputs.reusable != 'true'
- name: "Check disk space after build"
run: df -H
+
+ # Run checkout code in a separate job with no branch-cache publications.
This optional
+ # producer hands the snapshot only to consumers of the same workflow run.
+ snapshot-ci-images:
+ name: "Snapshot CI ${{ inputs.platform }} image ${{ matrix.python-version
}}"
+ needs: build-ci-images
+ if: >
+ github.event_name == 'pull_request' &&
+ inputs.upload-image-artifact == 'true' && inputs.image-stash-ref == ''
+ continue-on-error: true
+ timeout-minutes: 20
+ runs-on: ${{ fromJSON(inputs.runners) }}
+ permissions:
+ contents: read
+ strategy:
+ fail-fast: false
+ matrix:
+ python-version: ${{ fromJSON(inputs.python-versions) }}
+ env:
+ PYTHON_MAJOR_MINOR_VERSION: ${{ matrix.python-version }}
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ steps:
+ - name: "Checkout sources"
+ uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 #
v7.0.1
+ with:
+ ref: ${{ inputs.checkout-ref }}
+ persist-credentials: false
+ - name: "Prepare authoritative CI image"
+ uses: ./.github/actions/prepare_breeze_and_image
+ with:
+ platform: ${{ inputs.platform }}
+ python: ${{ matrix.python-version }}
+ use-uv: ${{ inputs.use-uv }}
+ make-mnt-writeable-and-cleanup: 'true'
+ - name: "Snapshot CI image ${{ inputs.platform }}:${{
env.PYTHON_MAJOR_MINOR_VERSION }}"
Review Comment:
## CodeQL / Cache Poisoning via execution of untrusted code
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([schedule](2)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](3)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([schedule](4)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](5)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](6)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](7)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](8)).
[Show more
details](https://github.com/apache/airflow/security/code-scanning/674)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]