Skip to content

feat(security): remove RSA PKCS1 cipher mode fallback — partial (W-17711863) #1019

feat(security): remove RSA PKCS1 cipher mode fallback — partial (W-17711863)

feat(security): remove RSA PKCS1 cipher mode fallback — partial (W-17711863) #1019

Workflow file for this run

name: Pull Request
on:
# Pull_request_target is required to grant secrets/write-permission to fork PRs.
# Mitigated by per-job Member Check (see "Check Write Permission" + "Validate Write Permission" steps).
# Reference: team Github Actions Tribal Knowledge doc.
pull_request_target: # zizmor: ignore[dangerous-triggers]
branches: [dev, master]
paths-ignore:
- '**/*.md'
- 'LICENSE'
- '.gitignore'
- 'CODEOWNERS'
permissions:
contents: read
jobs:
test-orchestrator:
runs-on: forcedotcom-ubuntu # forks: use ubuntu-latest (org-scoped runner)
permissions:
contents: read
pull-requests: write
env:
BUNDLE_GEMFILE: ${{ github.workspace }}/.github/DangerFiles/Gemfile
outputs:
libs: ${{ steps.test-orchestrator.outputs.libs }}
run_all_ui_tests: ${{ steps.test-orchestrator.outputs.run_all_ui_tests }}
steps:
- name: Check Write Permission
uses: octokit/request-action@dad4362715b7fb2ddedf9772c8670824af564f0d # v2.4.0
id: check_permissions
with:
route: GET /repos/${{ github.repository }}/collaborators/${{ github.triggering_actor }}/permission
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Debug Permission Response
env:
PERMISSION_DATA: ${{ steps.check_permissions.outputs.data }}
run: |
echo "Permission raw response: ${PERMISSION_DATA}"
- name: Validate Write Permission
env:
PERMISSION: ${{ fromJson(steps.check_permissions.outputs.data).permission }}
TRIGGERING_ACTOR: ${{ github.triggering_actor }}
run: |
echo "User ${TRIGGERING_ACTOR} has permission: ${PERMISSION}"
if [ "${PERMISSION}" != "write" ] && [ "${PERMISSION}" != "admin" ]; then
echo "User ${TRIGGERING_ACTOR} does not have sufficient permission (write or admin) to proceed. Someone from the team needs to rerun this workflow AFTER it has been deemed safe."
exit 1
fi
- name: Checkout
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
# We need a sufficient depth or Danger will occasionally run into issues checking which files were modified.
fetch-depth: 100
# This is dangerous without the member check
ref: ${{ github.event.pull_request.head.sha }}
- uses: ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f # v1.310.0
with:
ruby-version: '3.2'
bundler-cache: true
- name: Determine Tests to Run
id: test-orchestrator
env:
DANGER_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: bundle exec danger --dangerfile=.github/DangerFiles/TestOrchestrator.rb --danger_id="TestOrchestrator"
unit-tests-pr:
permissions:
contents: read
pull-requests: write
needs: [test-orchestrator]
strategy:
fail-fast: false
matrix:
lib: ${{ fromJson(needs.test-orchestrator.outputs.libs) }}
uses: ./.github/workflows/reusable-lib-workflow.yaml
with:
lib: ${{ matrix.lib }}
is_pr: true
secrets:
TEST_CREDENTIALS: ${{ secrets.TEST_CREDENTIALS }}
GCLOUD_SERVICE_KEY: ${{ secrets.GCLOUD_SERVICE_KEY }}
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
ui-tests-pr:
permissions:
contents: read
pull-requests: write
needs: [test-orchestrator]
uses: ./.github/workflows/reusable-ui-workflow.yaml
with:
is_pr: true
run_all_ui_tests: ${{ needs.test-orchestrator.outputs.run_all_ui_tests == 'true' }}
secrets:
MSDK_ANDROID_REMOTE_ACCESS_CALLBACK_URL: ${{ secrets.MSDK_ANDROID_REMOTE_ACCESS_CALLBACK_URL }}
MSDK_ANDROID_REMOTE_ACCESS_CONSUMER_KEY: ${{ secrets.MSDK_ANDROID_REMOTE_ACCESS_CONSUMER_KEY }}
UI_TEST_CONFIG: ${{ secrets.UI_TEST_CONFIG }}
GCLOUD_SERVICE_KEY: ${{ secrets.GCLOUD_SERVICE_KEY }}
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}