Skip to content

ci: fix main push workflow validation - #475

Merged
vicondoa merged 2 commits into
mainfrom
fix/buildbuddy-push-validation
Aug 22, 2026
Merged

vicondoa merged 2 commits into
mainfrom
fix/buildbuddy-push-validation

Conversation

@vicondoa

Copy link
Copy Markdown
Owner

Summary

Fix the three multiline POSIX [ provenance tests in build.yaml. Bash accepted the old form during syntax-only validation but the trusted main push run failed at runtime with [: missing \]'`, leaving the metadata and aggregate build checks red. The comparisons are unchanged; only their shell command shape is corrected.

This is a follow-up to #474, which landed the main-controlled workflow and v3 policy. It does not modify v3 or use #473 as a vehicle.

Validation

  • Parsed .github/workflows/build.yaml and passed every embedded run script through bash -n.
  • Exercised the metadata script with representative push and pull_request_target environments; both reached and passed immutable OID/provenance validation.
  • git diff --check passed.
  • Fresh independent P0/P1 correctness and security review found no actionable findings.

Security and trust boundaries

The fix does not change workflow refs, immutable OID checks, local-only Nix/fixture/hardware behavior, BuildBuddy target selection, credential descriptor handling, or the push-only credential gate. PR workflows remain credential-free and main-controlled.

@vicondoa
vicondoa merged commit 6c56e30 into main Aug 22, 2026
47 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant