github-advanced-security[bot] commented on code in PR #74173:
URL: https://github.com/apache/airflow/pull/74173#discussion_r4174491243
##########
.github/workflows/ci-image-build.yml:
##########
@@ -321,6 +321,55 @@
docker rmi "${CACHE_FROM_IMAGE}"
shell: bash
if: always() && env.CACHE_FROM_IMAGE != ''
+ - name: "Export mount cache ${{ inputs.platform }}:${{
env.PYTHON_MAJOR_MINOR_VERSION }}"
+ env:
+ PYTHON_MAJOR_MINOR_VERSION: ${{ env.PYTHON_MAJOR_MINOR_VERSION }}
+ run: >
+ breeze ci-image export-mount-cache
+ --cache-file
/tmp/ci-cache-mount-save-v3-${PYTHON_MAJOR_MINOR_VERSION}.tar.gz
+ if: >
+ inputs.upload-mount-cache-artifact == 'true' &&
+ steps.stashed-image.outputs.reusable != 'true'
+ - name: >
+ Stash cache mount ${{ inputs.platform }}:${{
env.PYTHON_MAJOR_MINOR_VERSION }}
+ ${{ inputs.image-stash-ref != '' && format('for ref {0}',
inputs.image-stash-ref) || '' }}
+ uses:
apache/infrastructure-actions/stash/save@61dcea11f19e2bbe1263f14d72235e8da17d3ad0
# save/v1.0.0
+ with:
+ key: "ci-cache-mount-save-v3-${{ inputs.platform }}-${{
env.PYTHON_MAJOR_MINOR_VERSION }}\
+ ${{ inputs.image-stash-ref != '' && format('-{0}',
inputs.image-stash-ref) || '' }}"
+ path: "/tmp/ci-cache-mount-save-v3-${{
env.PYTHON_MAJOR_MINOR_VERSION }}.tar.gz"
+ if-no-files-found: 'error'
+ # A ref's cache is read by the next publish of that same ref, days
rather than hours
+ # later, so it gets the retention the ref's image gets rather than
the branch's.
+ retention-days: ${{ inputs.image-stash-ref != '' && '6' || '2' }}
+ if: >
+ inputs.upload-mount-cache-artifact == 'true' &&
+ steps.stashed-image.outputs.reusable != 'true'
+ # Every job that prepares the CI image would otherwise `docker image
load` the stash below,
+ # unpacking and checksumming each layer again; a copy of the image store
restores with one
+ # extraction. Taken while the freshly built layers are still in the page
cache, and after the
+ # mount cache export, as it drops the build cache that the export reads.
+ - name: "Snapshot CI image ${{ inputs.platform }}:${{
env.PYTHON_MAJOR_MINOR_VERSION }}"
+ env:
+ PLATFORM: ${{ inputs.platform }}
+ run: >
+ ./scripts/ci/docker_data_root_snapshot.sh create
+
"/mnt/ci-image-snapshot-${PLATFORM//\//_}-${PYTHON_MAJOR_MINOR_VERSION}.tar.zst"
+ shell: bash
+ if: >
+ inputs.upload-image-artifact == 'true' && inputs.image-stash-ref ==
'' &&
+ steps.stashed-image.outputs.reusable != 'true'
+ - name: "Stash CI image snapshot ${{ inputs.platform }}:${{
env.PYTHON_MAJOR_MINOR_VERSION }}"
Review Comment:
## CodeQL / Cache Poisoning via execution of untrusted code
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([schedule](2)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](3)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([schedule](4)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](5)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](6)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](7)).
Potential cache poisoning in the context of the default branch due to
privilege checkout of untrusted code from [inputs.checkout-ref](1).
([workflow_dispatch](8)).
[Show more
details](https://github.com/apache/airflow/security/code-scanning/669)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]