mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path Trusted workflow-dispatch runs execute an authorized target SHA, but GitHub context still describes the default-branch workflow revision. Retained paid results and artifact names were therefore labeling target-branch executions as master. The workflow must explicitly pass its authorized target coordinates to target code and trusted reporting. ## What Changed - emit the canonical authorized target ref alongside the immutable target SHA - pass those coordinates to paid cells and the trusted report - name shared build/provider artifacts with the target SHA rather than workflow SHA - add workflow-security coverage for all trusted provenance wiring ## Verification - focused workflow-security tests: 6/6 passed - Prettier and git diff checks passed - run 33823252706 independently proved the pre-fix defect: functionally green target cells were retained as master SHA0ad180b85instead of feature SHA33c7646d3## Risks The execution checkout and secret boundary were already pinned correctly; this changes retained attribution and artifact labels only. Target-side report code on PR #12769 consumes these trusted environment values and overwrites untrusted cell metadata. ## Model Used Codex (GPT-5)
36 lines
1.1 KiB
TypeScript
36 lines
1.1 KiB
TypeScript
import type { RunnerE2EResult } from "./types.js";
|
|
|
|
type RunnerE2ESource = NonNullable<RunnerE2EResult["source"]>;
|
|
|
|
function nonEmpty(value: string | null | undefined) {
|
|
const normalized = value?.trim();
|
|
return normalized ? normalized : null;
|
|
}
|
|
|
|
function workflowRunUrl(environment: NodeJS.ProcessEnv) {
|
|
const serverUrl = nonEmpty(environment.GITHUB_SERVER_URL);
|
|
const repository = nonEmpty(environment.GITHUB_REPOSITORY);
|
|
const runId = nonEmpty(environment.GITHUB_RUN_ID);
|
|
return serverUrl && repository && runId
|
|
? `${serverUrl}/${repository}/actions/runs/${runId}`
|
|
: null;
|
|
}
|
|
|
|
export function resolveRunnerE2ESource(
|
|
existing?: RunnerE2ESource | null,
|
|
environment: NodeJS.ProcessEnv = process.env,
|
|
): RunnerE2ESource {
|
|
return {
|
|
sha:
|
|
nonEmpty(environment.PAPERCLIP_RUNNER_E2E_SOURCE_SHA) ??
|
|
nonEmpty(existing?.sha) ??
|
|
nonEmpty(environment.GITHUB_SHA),
|
|
ref:
|
|
nonEmpty(environment.PAPERCLIP_RUNNER_E2E_SOURCE_REF) ??
|
|
nonEmpty(existing?.ref) ??
|
|
nonEmpty(environment.GITHUB_REF),
|
|
workflowRunUrl:
|
|
workflowRunUrl(environment) ?? nonEmpty(existing?.workflowRunUrl),
|
|
};
|
|
}
|