Repository navigation
ci: publish docs from 4.18.1.x with the default branch's workflow - #1141
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: QUIET Plan: Advanced Run ID: 📒 Files selected for processing (2)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe documentation publishing workflow was replaced. The new workflow builds documentation, checks Javadoc output, deploys to GitHub Pages, and reports missing build or API output. Priority: ➖ Normal Change: Bug fix Merge Risk: ⚪ Minimal · up to The documentation publishing workflow now uses pinned actions and write permission, and it reports missing Javadoc output after publishing. Publishing still updates the versions that built successfully, as before. No merge-blocking issue was found. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The workflow explicitly authorizes documentation publishing and improves action pinning and build-loss detection. No newly introduced vulnerability was established. Risk remains low rather than minimal because effective actor permissions and repository protections were not verified, and a failed or canceled publication does not automatically restore the previous site. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This branch's docs-pages.yaml uses unpinned actions, which the org now rejects at Set up job, and has no contents: write, so deploy.sh would get a 403 anyway. Docs changes here never reach the site. Replace it with scylla-4.x's docs-pages.yml. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
c153344 to
37f210b
Compare
Depends on: nothing
Blocks: #1144
A docs push to this branch publishes nothing. Its
docs-pages.yamluses unpinned actions (actions/checkout@v4, …), which the org now rejects at Set up job. It also has nocontents: write, so even if it ran,deploy.shwould fail with a 403, asscylla-3.xrun 35871167922 did. Without this PR, #1144's pages never reach the site.docs-pages.yamlwithscylla-4.x'sdocs-pages.yml(pinned actions, write permission, JDK 8+11, javadoc guard)The branch already is 4.18.1.0 plus docs commits, and its own
javadoc.shworks (plugin 3.2.0 writestarget/site, which it reads), so nothing else changes.CI: every
tests@v1job fails at Set up job for the same unpinned-actions reason in this branch's[email protected]. Pre-existing and unrelated to this diff.Verified:
git diff origin/scylla-4.x -- .github/workflows/docs-pages.ymlis empty, and a local four-version multiversion build published 1152 javadoc files for this version, the same as the live site. Not covered: the workflow itself. Merging touches nopathsentry, so nothing runs. After merge, before #1144, rungh workflow run docs-pages.yml --ref scylla-4.18.1.xand check thatscylla-4.18.1.x/api/is still live.Refs: #1133
Jira: DRIVER-1108
🤖 Generated with Claude Code