From 871e3e844a4f6bed85941052b710333d33b467e8 Mon Sep 17 00:00:00 2001 From: tgwab-claude <326333458+tgwab-claude@users.noreply.github.com> Date: Wed, 16 Sep 2026 12:50:38 -0400 Subject: [PATCH] ci: stamp commit hash and message on Pages direct-upload deploy wrangler pages deploy on a direct upload does not record the shipped commit unless told to, so the deploy-drift audit can report a repo as behind when the content is current (see MichalAFerber/audio-viewer.us#14). Adds --commit-hash and --commit-message, sourced from github.sha and the commit/PR-title event fields, passed through env vars and referenced with "$VAR" rather than interpolated into the run: text, since a commit message or PR title is attacker-influenceable. Same fix as MichalAFerber/audio-viewer.us#15, applied identically across the File Viewer family. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01XE6Up1JPpFrhM5tC8hvHDE --- .github/workflows/deploy.yml | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 0fe15e8..697a51e 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -53,8 +53,13 @@ jobs: env: CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID || '8a0d49b1f3fdcdadec135562ec8a4fdc' }} - run: > - npx wrangler@4 pages deploy . - --project-name file-web-viewer - --branch ${{ github.ref == 'refs/heads/main' && 'main' || github.head_ref }} - --commit-dirty=false + DEPLOY_BRANCH: ${{ github.ref == 'refs/heads/main' && 'main' || github.head_ref }} + COMMIT_HASH: ${{ github.sha }} + COMMIT_MESSAGE: ${{ github.event.head_commit.message || github.event.pull_request.title }} + run: | + npx wrangler@4 pages deploy . \ + --project-name file-web-viewer \ + --branch "$DEPLOY_BRANCH" \ + --commit-hash "$COMMIT_HASH" \ + --commit-message "$COMMIT_MESSAGE" \ + --commit-dirty=false