Fix CI pipeline: use Docker Hub image + fix security audit #24
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix-pipeline-image-pull"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
archlinux:latestfrom Docker Hub with inline dep installationSpaceInsideArrayLiteralBracketsoffensesChanges
.woodpecker.yaml: Replace Harbor image witharchlinux:latest, add inline pacman install of ruby/libyaml/base-devel/gitGemfile.lock: Update omniauth 1.9.2 → 2.1.4 (+ rack, rack-session, rackup, rack-protection)config/initializers/omniauth.rb: Fix array bracket spacingconfig/routes.rb: Fix array bracket spacingTest Plan
Review Checklist
Related Notes
ldraney/pal-enterprises #19— original pipeline implementation (closed)PR #24 Review
CI Pipeline
archlinux:latestfrom Docker Hub is valid fix for image pull failure (#23)OmniAuth Upgrade (1.9.2 → 2.1.4)
allowed_request_methods = [:post, :get]for Keycloak redirect flow — intentionalomniauth-rails_csrf_protectiongem present,pkce: trueset — good security postureBlockers
None.
Nits
allowed_request_methods(Keycloak redirect)SOP
fix-pipeline-image-pullvs23-fix-pipeline-image-pull— minor deviation, non-blocking for hotfixVERDICT: APPROVED
Correctly fixes CI pipeline image pull (#23), upgrades omniauth for CVE-2015-9284, cleans rubocop offenses. No blockers.