Skip to content

ci: publish docs from 4.18.1.x with the default branch's workflow - #1141

Merged
dkropachev merged 1 commit into
scylladb:scylla-4.18.1.xfrom
nikagra:fix-4181-docs-build
Oct 1, 2026
Merged

dkropachev merged 1 commit into
scylladb:scylla-4.18.1.xfrom
nikagra:fix-4181-docs-build

Conversation

@nikagra

@nikagra nikagra commented Sep 24, 2026 •

Copy link
Copy Markdown

Depends on: nothing
Blocks: #1144

A docs push to this branch publishes nothing. Its docs-pages.yaml uses unpinned actions (actions/checkout@v4, …), which the org now rejects at Set up job. It also has no contents: write, so even if it ran, deploy.sh would fail with a 403, as scylla-3.x run 35871167922 did. Without this PR, #1144's pages never reach the site.

  • replace docs-pages.yaml with scylla-4.x's docs-pages.yml (pinned actions, write permission, JDK 8+11, javadoc guard)

The branch already is 4.18.1.0 plus docs commits, and its own javadoc.sh works (plugin 3.2.0 writes target/site, which it reads), so nothing else changes.

CI: every tests@v1 job fails at Set up job for the same unpinned-actions reason in this branch's [email protected]. Pre-existing and unrelated to this diff.

Verified: git diff origin/scylla-4.x -- .github/workflows/docs-pages.yml is empty, and a local four-version multiversion build published 1152 javadoc files for this version, the same as the live site. Not covered: the workflow itself. Merging touches no paths entry, so nothing runs. After merge, before #1144, run gh workflow run docs-pages.yml --ref scylla-4.18.1.x and check that scylla-4.18.1.x/api/ is still live.

Refs: #1133
Jira: DRIVER-1108

🤖 Generated with Claude Code

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: bf46670c-9168-43c9-be5e-86eb3fd78ec0

📥 Commits

Reviewing files that changed from the base of the PR and between 658bca5 and 37f210b.

📒 Files selected for processing (2)
  • .github/workflows/docs-pages.yaml
  • .github/workflows/docs-pages.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/docs-pages.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The documentation publishing workflow was replaced. The new workflow builds documentation, checks Javadoc output, deploys to GitHub Pages, and reports missing build or API output.

Priority: ➖ Normal

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 37f21

The documentation publishing workflow now uses pinned actions and write permission, and it reports missing Javadoc output after publishing. Publishing still updates the versions that built successfully, as before. No merge-blocking issue was found.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 37f21

The workflow explicitly authorizes documentation publishing and improves action pinning and build-loss detection. No newly introduced vulnerability was established. Risk remains low rather than minimal because effective actor permissions and repository protections were not verified, and a failed or canceled publication does not automatically restore the previous site.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The intended privileged outcome is replacement of this repository's published documentation, including all versions in the generated tree. A compromised writer could potentially affect other repository contents permitted by contents: write, not only gh-pages; actual reach depends on branch rules and effective token policy. The inspected path does not establish cross-repository or production-service authority.

Trust Boundaries and Controls

  • inferred — There is no direct pull-request trigger. Commit-pinned actions, default-branch checkout, disabled credential persistence, and fixed origin version inputs constrain the path. Nevertheless, executable build inputs and later token-bearing deployment share a runner. Compromise of a selected build ref or dependency could persist into deployment; who can alter those inputs or execute modified workflow definitions is not established by the supplied runtime evidence. This is a conditional trust-boundary exposure, not a verified unprivileged exploit or a proven increase over effective base permissions.

Resilience and Maintainability Implications

  • observed — The new validation adds a total-loss containment control and visible partial-loss reporting. It does not make publication transactional. The force-push replacement mechanism and lack of an in-workflow restoration path already existed, so they are architecture facts rather than newly introduced security findings.

Hardening Proposals

  • proposed — Confirm protection of workflow definitions and selected build branches, dispatch eligibility, and effective token restrictions. If stronger build-compromise containment is required, separate uncredentialed builds from a fresh deployment job with write authority and a defined artifact handoff.
  • proposed — If recovery from an authorized but incorrect publication is a requirement, retain a known-good publication snapshot and define restoration independently of the canceled or failed workflow's final status.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the CI workflow change and its purpose: publishing documentation from the 4.18.1.x branch using the default branch's workflow.
Description check ✅ Passed The description directly explains the workflow replacement, the publishing failures it addresses, and the validation performed.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch's docs-pages.yaml uses unpinned actions, which the org now
rejects at Set up job, and has no contents: write, so deploy.sh would
get a 403 anyway. Docs changes here never reach the site. Replace it
with scylla-4.x's docs-pages.yml.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@nikagra
nikagra force-pushed the fix-4181-docs-build branch from c153344 to 37f210b Compare October 1, 2026 18:01
@nikagra
nikagra marked this pull request as ready for review October 1, 2026 18:02
@nikagra
nikagra requested a review from dkropachev October 1, 2026 18:03
@dkropachev
dkropachev merged commit facff43 into scylladb:scylla-4.18.1.x Oct 1, 2026
7 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants