Skip to content

test: run ITS pipeline e2e checks on pull requests - #3574

Open
dheerajodha wants to merge 10 commits into
conforma:mainfrom
dheerajodha:codex/ec-1943-its-pr-ci
Open

dheerajodha wants to merge 10 commits into
conforma:mainfrom
dheerajodha:codex/ec-1943-its-pr-ci

Conversation

@dheerajodha

@dheerajodha dheerajodha commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Changes to the enterprise-contract ITS pipeline need pre-merge E2E validation. Add a separate Pipelines-as-Code check for PRs targeting main that change pipelines/enterprise-contract/** or this trigger. It runs only the ITS suite and reports the result on the CLI PR.

The runner and test suite are pinned independently of the pipeline under test. The ITS definition is fetched from the PR source URL and exact commit SHA, including fork PRs. The definition retains its own task bundle references; this check does not build a custom CLI image.

Dependency and authorization

Depends on conforma/e2e-tests#12 (EC-1943). This PR can be reviewed now, but must not merge until that dependency lands and the source pins are updated. For pre-merge testing, both runner/test source URLs temporarily use https://github.com/dheerajodha/conforma-e2e-tests.git at 4bbba993a3b44eec5debb89fbc4f8bd1c8d0503d. Before merge, restore both URLs to https://github.com/conforma/e2e-tests.git and both pins to the resulting merged upstream commit.

Matching uses normalized event, target branch, and changed paths. Execution authorization relies on Pipelines-as-Code ACLs and approval policy. Verify the tenant's deployed Repository/global authorization configuration before merge; it has not yet been inspected. A raw-webhook author-association filter was removed because event payload differences prevented execution. The outer runner is pinned to a fixed E2E commit; only the ITS definition under test uses the PR source URL and revision. Pipelines-as-Code documents ACL checks before execution, including /ok-to-test approval for unauthorized contributors: https://pipelinesascode.com/docs/guides/running-pipelines/#acl-permissions-for-triggering-pipelineruns. An author filter inside a PR-editable trigger is not a substitute for that external authorization boundary.

Validation

  • Positive baseline: cli-its-on-pull-request-t6hlv tested CLI commit 257252cb; all three ITS scenarios passed.
  • Confirmed negative test: cli-its-on-pull-request-v6kmv tested CLI commit b6987722. Image building, signing, and attestation succeeded. The ITS PipelineRun then failed with CouldntGetTask and MANIFEST_UNKNOWN for the deliberately nonexistent bundle tag ec-1943-deliberately-missing-round2. The success scenario failed and the E2E step exited 1; the other two ordered scenarios were skipped.
  • Restored positive validation: cli-its-on-pull-request-sq7br passed against CLI commit 455530c490a3a4f4a79a54a60dd220730a31f687, with the valid quay.io/conforma/tekton-task:konflux reference restored.
  • The rebased suite compiles and passes dry-run selection; Tekton schema and parameter-wiring validation passed.
  • Rechecked at 6ead7e45: every supplied parameter name/type matches the runner at 4bbba993; both runner/test source pins agree; no deliberate-break bundle tag remains. The PR changes only the trigger file.

Negative-run logs: https://konflux-ui.apps.stone-prd-rh01.pg1f.p1.openshiftapps.com/ns/rhtap-contract-tenant/pipelinerun/cli-its-on-pull-request-v6kmv/logs/conforma-e2e-tests

Before merge

  • Merge feat: add e2e test coverage for the ITS pipeline e2e-tests#12, replace both source URLs with https://github.com/conforma/e2e-tests.git, and set both revisions to the resulting upstream commit.
  • Validate the parameter contract and rerun ITS against that upstream pin.
  • Inspect the deployed PaC Repository/global policy and confirm unauthorized contributors cannot run this job without authorized approval. The latest inspection attempt could not authenticate to the cluster; this prerequisite remains unverified.

Remaining rollout work

Complete required-check enforcement without leaving unrelated PRs waiting for a path-filtered check. Keep EC-1943 open until merge protection is active. Separately investigate the artifact collection permission errors seen in the negative run; they did not cause the confirmed bundle-resolution failure.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: 4ffaa825-50f0-46e3-a246-645e885b3aba

📥 Commits

Reviewing files that changed from the base of the PR and between 65cf118 and 6ead7e4.

📒 Files selected for processing (1)
  • .tekton/cli-its-pull-request.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

Adds a Tekton PipelineRun that runs for pull requests targeting main when specified Enterprise Contract pipeline files or this configuration file change. The run sets its repository, revision, pipeline parameters, label filter, and service account.

Changes

Enterprise Contract pull request pipeline

Layer / File(s) Summary
Configure and run the pull request pipeline
.tekton/cli-its-pull-request.yaml
Defines pull request triggers and run retention settings. Configures the e2e test repository, pinned revision, pipeline path, label filter, pipeline resolution, and service account.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: acepresso, bohdanmar

Merge Risk: ⚪ Minimal · up to 6ead7

No confirmed issue blocks this change. Confirm required-check behavior for unrelated pull requests before enabling enforcement.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the main change: running ITS pipeline end-to-end checks on pull requests.
Description check ✅ Passed The description explains what changed, why it is needed, validation results, dependencies, and before-merge work. It does not use the template's separate Tickets heading, but it includes the related d…
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Re-review anchoring preserves prior moderate (2) score: Tier 1 signals are unchanged (single new .tekton/ file, 53 lines, small blast radius, returning contributor, no protected paths, no dependencies), Tier 2 defaults to 2 for a new file, and the blocking cross-repo dependency (conforma/e2e-tests#12) that the prior assessor flagged remains unmerged — no signal justifies lowering from the prior score.

Previous run

Risk Assessment: moderate (2/5)

Details

Single-file Tekton CI pipeline addition (57 lines) by a returning contributor with small blast radius and no security concerns per Tier 1 signals; fork pins remain unresolved but debug tag was removed since prior assessment, keeping composite steady at moderate.

Previous run (2)

Risk Assessment: moderate (2/5)

Details

Small config-only PR (59 lines, 2 files) adding a new CI trigger with a deliberately-broken bundle tag and fork-pinned refs; the debug-tag and fork pins are acknowledged pre-merge restorations, and stable git history plus returning contributor keep composite at moderate.

Previous run (3)

Risk Assessment: low (1/5)

Details

Very small PR (2 files, 63 lines added, blast=small) with no protected paths, security-sensitive files, dependency changes, or CI workflow modifications by the Tier 1 script's classification. Author is a known human contributor. Primary risk factors are draft status and an unmerged external dependency (e2e-tests#12), which introduce coordination coupling but do not affect the code risk of the change itself. Composite T1=1.1, T2=1.1, T3=2 yields 1.29, rounding to 1 (low), consistent with the PR's own risk/low label.

Previous run (4)

Risk Assessment: low (1/5)

Details

Single small Tekton PipelineRun config file (54 lines) added under .tekton/. No protected paths, no security-sensitive content per the metadata script, no dependency changes, no GitHub Actions workflow changes. Author is a known human contributor. Tier 2 applies the all-files-new moderate baseline of 2. Weighted composite (Tier 1 62% x 1.125 + Tier 2 38% x 2) = 1.46, rounds to 1 (low). Note: this baseline score does not reflect the fork-code-execution risk raised as a high finding, which is qualitative and outside the Tier 1 signal set.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review

Since the prior review (SHA 455530c4), the only changes are removal of three inline comments — the substantive PipelineRun definition (CEL trigger, fork URL, pinned SHA, mounted secrets, service account) is unchanged. Under severity anchoring the prior high findings persist. Additionally, the PR has transitioned from draft to non-draft while the acknowledged pre-merge restoration requirements remain unresolved, and the inline reminders that partially documented those requirements have been stripped — leaving only the (author-controlled, non-durable) PR body as a warning. These findings must be addressed before merge.

Findings

High

  • [fail-open-authorization] .tekton/cli-its-pull-request.yaml:13 — The CEL trigger (lines 11-14) gates only on event == "pull_request", target_branch == "main", and pathChanged() over pipelines/enterprise-contract/** or .tekton/cli-its-pull-request.yaml itself. There is no author_association check and no ok-to-test label check — trust is delegated entirely to Pipelines-as-Code tenant ACLs. Amplifying facts verified against the file: (a) the CEL's pathChanged() clause at line 14 matches this file itself, so a fork PR editing it widens its own trigger surface; (b) pipelineRef (lines 43-51) resolves the pipeline body via the git resolver from a URL+revision pair currently pointing at a personal fork (line 47), meaning fork-controlled pipeline YAML would execute under serviceAccountName: konflux-integration-runner (line 53) with konflux-test-infra (line 30) and mapt-kind-secret (lines 32, 34) in scope. PaC's default fork-PR policy typically requires an owner/collaborator /ok-to-test — that mitigation is external and unverifiable from the diff.
    Remediation: Either (a) add an explicit CEL guard for trusted actors (e.g., pipelines_as_code.author_association in ["OWNER","MEMBER","COLLABORATOR"] or a hasLabel("ok-to-test") gate) so the trust posture is expressed in-tree, or (b) document the deployed tenant PaC Repository CR trust policy as a hard prerequisite. Independently, pin pipelineRef.url/revision (lines 47, 49) to a canonical conforma/* repository+SHA so fork-authored pipeline bodies cannot execute with the mounted secrets.

  • [unpinned-external-source] .tekton/cli-its-pull-request.yaml:24 — Both spec.params (git-url line 24, revision line 26) and pipelineRef (url line 47, revision line 49) reference the personal contributor fork https://github.com/dheerajodha/conforma-e2e-tests.git pinned to 4bbba993a3b44eec5debb89fbc4f8bd1c8d0503d. Per the PR body, the upstream dependency conforma/e2e-tests#12 is unmerged. Risks: (a) supply chain — the personal fork can be deleted, renamed, force-pushed, or account-compromised, and its content is resolved into a PipelineRun that mounts konflux-test-infra (line 30) and mapt-kind-secret (lines 32, 34) under konflux-integration-runner (line 53); (b) SHA-orphan — if conforma/e2e-tests#12 is squash-merged (GitHub default), the merge-commit SHA will differ from 4bbba99..., which will then exist only in the personal fork; (c) governance — a shared .tekton/ PipelineRun on main should reference the canonical org repository.
    Remediation: Block merge until conforma/e2e-tests#12 lands. Then repoint both git-url (line 24) and pipelineRef.url (line 47) to https://github.com/conforma/e2e-tests.git, and repin both revision fields (lines 26 and 49) to the upstream merge-commit SHA.

Medium

  • [merge-gate-absent] .tekton/cli-its-pull-request.yaml:24 — Process-risk observation layered on top of the unpinned-external-source finding: the PR has transitioned from draft to non-draft while the fork URL (lines 24, 47) and personal-fork SHA (lines 26, 49) remain in place, and inline reminders present in the prior revision have been removed. No repo-level automated check exists to reject .tekton/*.yaml files referencing URLs outside conforma/*. The only surviving warning is the PR body, which is author-controlled and dropped from git history on merge. See also: [unpinned-external-source] finding at this location.
    Remediation: Before merging: (1) replace both dheerajodha/conforma-e2e-tests.git references with conforma/e2e-tests.git (lines 24, 47), and (2) update the pinned revisions (lines 26, 49) once conforma/e2e-tests#12 lands. Longer term, add a repo-level lint or required status check that fails when .tekton/*.yaml references git URLs outside the conforma/* org.

Low

  • [api-contract] .tekton/cli-its-pull-request.yaml:35 — The params sent to the resolved pipeline (its-pipeline-repo-url, its-pipeline-revision, its-pipeline-path, test-label-filter, lines 35-42) diverge from the naming used by the sibling .tekton/cli-e2e-push.yaml (custom-ec-cli-url, custom-ec-cli-revision). Correctness depends on the fork's .tekton/pipelines/conforma-e2e/pipeline.yaml@4bbba99... declaring these exact param names; that pipeline file lives in another repository and cannot be verified from this diff. If any name/type is mismatched, the PipelineRun will fail admission or the params will be silently ignored.

  • [trigger-coverage-gap] .tekton/cli-its-pull-request.yaml:11 — The CEL only fires when pipelines/enterprise-contract/** or this file itself changes (lines 13-14). Changes to Task sources, Makefile, or CLI code paths that materially shape the built verify bundle will not trigger this ITS run. Informational; not a regression since this is a new job.

  • [param-propagation] .tekton/cli-its-pull-request.yaml:36 — its-pipeline-repo-url is bound to {{source_url}} (line 36) and its-pipeline-revision to {{revision}} (line 38). For fork PRs the runner fetches the pipeline-under-test from the contributor's fork at PR head — correct for the stated intent, but runs will fail for any PR whose fork is private or unreachable by the Konflux runner service account.

  • [missing-authorization] .tekton/cli-its-pull-request.yaml:1 — The PR references EC-1943 (external Jira) and depends on conforma/e2e-tests#12 (cross-repo). No linked issue in conforma/cli exists as an authorization record in this repo's public history. Not a code defect.
    Remediation: Open a tracking issue in conforma/cli mirroring EC-1943 and link it from the PR.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run

Review

Since the prior review (SHA b6987722), the debug bundle tag on pipelines/enterprise-contract/0.1/enterprise-contract.yaml:167 was reverted to :konflux, resolving the prior unreverted-debug-change and supply-chain-tag-squat concerns. The trigger file .tekton/cli-its-pull-request.yaml is unchanged since the prior head; prior findings on it persist under severity anchoring. Findings below must be addressed before this PR leaves draft.

Findings

High

  • [fail-open-authorization] .tekton/cli-its-pull-request.yaml:13 — CEL expression (lines 13-16) filters only on event, target_branch, and pathChanged() — no author_association or ok-to-test label gate. Authorization is deferred entirely to Pipelines-as-Code ACLs/approval policy, and the PR body explicitly states the tenant PaC Repository/global configuration has not yet been inspected. If that configuration is default-permissive, absent, or misconfigured, a fork pull_request touching the matched paths will trigger this PipelineRun under service account konflux-integration-runner (line 57) with konflux-test-infra (line 33) and mapt-kind-secret (lines 35, 37) mounted. Two amplifying facts confirmed in-file: (a) ".tekton/cli-its-pull-request.yaml".pathChanged() at line 16 lets a fork PR editing this very file widen its own trigger surface; (b) pipelineRef at lines 47-55 resolves the pipeline body from {{source_url}}@{{revision}} (the fork at PR head), so fork-controlled pipeline YAML would execute with the above secrets in scope.
    Remediation: Add an explicit CEL guard for trusted actors (e.g., pipelines_as_code.author_association in ["OWNER","MEMBER","COLLABORATOR"] or an ok-to-test label check), OR block merge until the deployed PaC Repository CR is inspected and documented as a hard prerequisite in the file header. Additionally pin pipelineRef to a canonical conforma/* repo+SHA rather than {{source_url}}@{{revision}} so fork-authored pipeline bodies cannot execute with these secrets.

  • [unpinned-external-source] .tekton/cli-its-pull-request.yaml:27 — Both spec.params (git-url line 27, revision line 29) and pipelineRef (url line 51, revision line 53) reference the personal contributor fork https://github.com/dheerajodha/conforma-e2e-tests.git pinned to 4bbba993a3b44eec5debb89fbc4f8bd1c8d0503d. Per the PR body, the upstream dependency conforma/e2e-tests#12 is unmerged. Three concrete risks converge: (a) supply chain — the fork can be deleted, renamed, or compromised, and its content is resolved into a PipelineRun that mounts konflux-test-infra and mapt-kind-secret; (b) SHA-orphan — if conforma/e2e-tests#12 is squash-merged (GitHub default), the merge-commit SHA will differ from 4bbba99..., which then exists only in the personal fork; (c) governance — a shared .tekton/ PipelineRun on main should reference the canonical org repository. Correctness of the four params sent to the resolved pipeline (its-pipeline-repo-url, its-pipeline-revision, its-pipeline-path, test-label-filter) also depends on whatever the fork commit contains, with no upstream guarantee once the fork is landed.
    Remediation: Block merge until conforma/e2e-tests#12 lands. Then repoint both git-url/pipelineRef.url to https://github.com/conforma/e2e-tests.git and repin both revision fields to the upstream merge-commit SHA.

Medium

  • [merge-gate-absent] .tekton/cli-its-pull-request.yaml:27 — Two acknowledged pre-merge restoration requirements are enforced only by draft status and inline prose comments (lines 25 and 46): (1) git-url and pipelineRef.url must be switched from dheerajodha/conforma-e2e-tests to conforma/e2e-tests, and (2) the pinned SHA must be updated to the merged canonical commit. No automated check rejects .tekton/*.yaml referencing repos outside conforma/*, so merge is technically possible without the restoration and enforcement relies on reviewer memory.
    Remediation: Before lifting draft, complete the fork/SHA restoration. Longer term, add a repo-level lint or pre-merge status check that fails when .tekton/*.yaml references git URLs outside conforma/*, or add explicit checklist items in CODEOWNERS or a PR template.

Low

  • [api-contract] .tekton/cli-its-pull-request.yaml:44 — The params sent to the resolved pipeline (its-pipeline-repo-url, its-pipeline-revision, its-pipeline-path, test-label-filter) diverge from the naming used by the sibling .tekton/cli-e2e-push.yaml (custom-ec-cli-url, custom-ec-cli-revision). Correctness depends on the fork's .tekton/pipelines/conforma-e2e/pipeline.yaml@4bbba99... declaring these exact param names; the referenced pipeline file cannot be inspected from this diff. If any name/type is mismatched, the PipelineRun will fail admission or the params will be silently ignored.
    Remediation: When repointing to upstream (per the unpinned-external-source finding), verify each of the four param names exists in conforma/e2e-tests's .tekton/pipelines/conforma-e2e/pipeline.yaml at the pinned SHA. A one-time dry run against the upstream SHA before flipping out of draft is sufficient.

  • [api-shape] .tekton/cli-its-pull-request.yaml:29 — The SHA 4bbba993... appears twice (lines 29 and 53) with a prose comment at line 46 asking humans to keep them coupled. A YAML anchor/alias would express the coupling structurally and eliminate the risk of silent drift when the SHA is bumped.
    Remediation: Define a YAML anchor on the first occurrence (value: &e2e-rev 4bbba993...) and reference it with an alias on the second (value: *e2e-rev). Remove the coupling comment — the anchor makes the relationship self-documenting.

  • [trigger-coverage-gap] .tekton/cli-its-pull-request.yaml:15 — The CEL only fires when pipelines/enterprise-contract/** or this file itself changes. Changes to Task source, Makefile, or CLI code paths that materially shape the built verify bundle will not trigger this ITS run. Informational; not a regression since this is a new job.

  • [param-propagation] .tekton/cli-its-pull-request.yaml:38 — its-pipeline-repo-url is bound to {{source_url}} and its-pipeline-revision to {{revision}}. For fork PRs the runner fetches the pipeline-under-test from the contributor's fork at PR head — correct for the stated intent, but runs will fail for any PR whose fork is private or unreachable by the Konflux runner service account.

  • [missing-authorization] .tekton/cli-its-pull-request.yaml:1 — The PR references EC-1943 (external Jira) and depends on conforma/e2e-tests#12 (cross-repo). No linked issue in conforma/cli exists as an authorization record in this repo's public history.
    Remediation: Open a tracking issue in conforma/cli mirroring EC-1943 and link it from the PR.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (2)

Review

Since the prior review (SHA 0a5ce00c), only .tekton/cli-its-pull-request.yaml was rewritten. That rewrite removed the CEL author_association allowlist that had been the sole in-file authorization gate; the file now relies entirely on Pipelines-as-Code tenant policy for authorization, and the PR body itself notes that tenant configuration has not been inspected. The prior cel-dead-branch concern is resolved (the body.comment clause was removed). pipelines/enterprise-contract/0.1/enterprise-contract.yaml was not modified; the deliberately-broken bundle tag pin and its scope-creep concern persist unchanged. Findings below must be addressed before this PR leaves draft.

Findings

Critical

  • [unreverted-debug-change] pipelines/enterprise-contract/0.1/enterprise-contract.yaml:167 — Line 167 pins verify-enterprise-contract to quay.io/conforma/tekton-task:ec-1943-deliberately-missing-round2, a deliberately-broken tag, while the sibling collect-keyless-params taskRef at line 113 remains :konflux. The file is internally inconsistent and every consumer at HEAD will fail bundle resolution at the verify step. This also exceeds the authorized scope of this PR ("add a PaC trigger for ITS"): the production pipeline is the artifact under test, not test infrastructure, so failure-scenario fixtures belong in the test pipeline or a scratch branch — not in the shared production pipeline definition. Restoration depends entirely on reviewer memory since no CI check enforces it. See also: [supply-chain-tag-squat] at this location.
    Remediation: Revert line 167 to quay.io/conforma/tekton-task:konflux (or an immutable digest). Drive any failing-ITS demo from the test-pipeline configuration rather than mutating the production pipeline file.

High

  • [fail-open-authorization] .tekton/cli-its-pull-request.yaml:13 — The CEL at lines 13-16 now filters only on event, target_branch, and pathChanged(); no author_association or label gate remains. The header comment defers authorization entirely to Pipelines-as-Code ACLs. If the deployed rhtap-contract-tenant PaC Repository/global policy is default-permissive, absent, or misconfigured (PR body: "that tenant configuration has not yet been inspected"), a fork PR touching the matched paths triggers this PipelineRun under konflux-integration-runner with konflux-test-infra and mapt-kind-secret in scope. The pathChanged filter includes this file itself, so a fork PR editing this file can widen the trigger surface. The runner pipelineRef body is also fetched from the fork at PR head (its-pipeline-repo-url={{source_url}}, its-pipeline-revision={{revision}}), so fork-controlled YAML executes with production secrets attached.
    Remediation: Restore an in-file authorization gate (author_association allowlist and/or ok-to-test label check) OR block merge until the deployed PaC Repository/global policy for rhtap-contract-tenant has been inspected and documented as a hard prerequisite in the file header. Alternatively, restrict its-pipeline-repo-url to a trusted upstream URL and copy the pipeline-under-test into a workspace.

  • [unpinned-external-source] .tekton/cli-its-pull-request.yaml:27 — Both spec.params (git-url line 27, revision line 29) and pipelineRef (url line 51, revision line 53) reference the personal contributor fork https://github.com/dheerajodha/conforma-e2e-tests.git at 4bbba993a3b44eec5debb89fbc4f8bd1c8d0503d. Per the PR body, the upstream dependency conforma/e2e-tests#12 is unmerged. Three concrete risks converge here: (a) supply chain — the fork can be deleted, renamed, or compromised, and the runner pipelineRef body is resolved from it into a workload holding konflux-test-infra and mapt-kind-secret; (b) SHA-orphan — if conforma/e2e-tests#12 is squash-merged, the merge-commit SHA will differ and both pins reference a commit that only exists in the personal fork; (c) governance — shared .tekton pipeline files should reference the canonical org repo.
    Remediation: Block merge until conforma/e2e-tests#12 lands. Then repoint both git-url and pipelineRef.url to https://github.com/conforma/e2e-tests.git and repin both revision fields to the upstream merge-commit SHA.

Medium

  • [merge-gate-absent] .tekton/cli-its-pull-request.yaml:27 — This PR carries at least two acknowledged pre-merge restoration requirements — fork-pinned refs in this trigger file (lines 27/29/51/53) and the deliberately-broken bundle tag in the companion pipeline file — guarded only by draft status and inline prose comments. No automated check rejects .tekton/*.yaml referencing repos outside conforma/*, and no check detects non-stable bundle tags in canonical pipeline files. Enforcement relies on reviewer memory across two files and three restorations.
    Remediation: Before lifting draft, complete the fork/SHA and bundle-tag restorations. Longer term, add a repo-level lint or pre-merge status check that fails when .tekton/*.yaml references git URLs outside conforma/* or when canonical pipeline files carry non-stable bundle tags.

Low

  • [supply-chain-tag-squat] pipelines/enterprise-contract/0.1/enterprise-contract.yaml:167 — Because :ec-1943-deliberately-missing-round2 currently does not resolve, if this file merges as-is a later actor with push rights to quay.io/conforma/tekton-task could create that tag with arbitrary content and downstream consumers would silently pick it up. Distinct future-tense supply-chain risk beyond the immediate resolution failure.
    Remediation: Restore :konflux or pin an image digest.

  • [api-shape] .tekton/cli-its-pull-request.yaml:29 — The pinned SHA 4bbba993... appears twice (lines 29 and 53) with an inline comment on line 46 asking humans to keep them coupled. A YAML anchor/alias would express the coupling structurally and prevent silent drift when the pin is rotated.
    Remediation: Introduce a YAML anchor on the first revision value and alias it at the second occurrence.

  • [trigger-coverage-gap] .tekton/cli-its-pull-request.yaml:15 — The CEL only fires when pipelines/enterprise-contract/** or this file itself changes. Changes to Task source, Makefile, or CLI code paths that shape the built verify bundle will not trigger this ITS run. Informational; not a regression since this is a new job.

  • [param-propagation] .tekton/cli-its-pull-request.yaml:38 — its-pipeline-repo-url is bound to {{source_url}} and its-pipeline-revision to {{revision}}. For fork PRs the runner fetches the pipeline-under-test from the contributor's fork at PR head — correct for the stated intent, but runs will fail for any PR whose fork is private or unreachable.

  • [missing-authorization] .tekton/cli-its-pull-request.yaml:1 — The PR references EC-1943 (external Jira) and depends on conforma/e2e-tests#12 (cross-repo). No linked issue in conforma/cli exists as an authorization record in this repo's public history.
    Remediation: Open a tracking issue in conforma/cli mirroring EC-1943 and link it from the PR.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (3)

Review

The CEL author_association gate added since the prior review (.tekton/cli-its-pull-request.yaml lines 15-18) closes the outside-fork trigger vector; the prior fork-controlled-code-with-secrets finding is downgraded to medium (residual issues: COLLABORATOR breadth, self-modifying trigger, fork-supplied pipeline body running under secret-bearing SA). Two blocking issues remain in the current head and one new one was introduced.

Findings

Critical

  • [unreverted-debug-change] pipelines/enterprise-contract/0.1/enterprise-contract.yaml:167 — Line 167 pins the verify-enterprise-contract bundle to quay.io/conforma/tekton-task:ec-1943-deliberately-missing-round2, the deliberately-broken tag used to demonstrate a failing ITS run. The PR body claims "The valid bundle reference is now restored," but HEAD contradicts that claim. The sibling taskRef at line 113 still points to :konflux, so this file is internally inconsistent as well. If merged, every consumer of this pipeline will fail to resolve the bundle at that step. See also: [scope-creep], [supply-chain-tag-squat] at this location.
    Remediation: Restore line 167 to quay.io/conforma/tekton-task:konflux (matching line 113) or an immutable digest pin before this PR leaves draft; otherwise update the PR body so intent matches state.

High

  • [scope-creep] pipelines/enterprise-contract/0.1/enterprise-contract.yaml:167 — The authorized scope of this PR ("add a Pipelines-as-Code trigger for ITS") does not cover mutating the production pipeline's task bundle reference. The production pipeline is the artifact under test, not test infrastructure; deliberate-break experiments belong in the referenced test pipeline or a scratch branch, not in the shared production pipeline definition. See also: [unreverted-debug-change] at this location.
    Remediation: Revert the bundle-tag change in enterprise-contract.yaml entirely; if a failing ITS demo is needed, drive it via the test-pipeline or a scratch commit rather than the production pipeline file.

  • [unpinned-external-source] .tekton/cli-its-pull-request.yaml:31 — Both the top-level params (git-url line 31, revision line 33) and the pipelineRef (url line 55, revision line 57) point at https://github.com/dheerajodha/conforma-e2e-tests.git @ 4bbba993a3b44eec5debb89fbc4f8bd1c8d0503d — a personal fork. Per the PR body the dependency feat: add e2e test coverage for the ITS pipeline e2e-tests#12 is unmerged, so the canonical upstream commit does not yet exist. See also: [supply-chain-fork-controlled-runner], [supply-chain-unmerged-dependency-pin] at this location.
    Remediation: Block merge until feat: add e2e test coverage for the ITS pipeline e2e-tests#12 lands. Then repoint both URLs to https://github.com/conforma/e2e-tests.git and both revisions to the merged upstream SHA.

  • [supply-chain-fork-controlled-runner] .tekton/cli-its-pull-request.yaml:55 — The runner pipelineRef body itself is resolved from a personal fork (url line 55, revision line 57) and executed under serviceAccount konflux-integration-runner with konflux-test-infra and mapt-kind-secret in scope. If the fork is deleted, made private, renamed (GitHub repository names are reusable — deletion followed by same-name repo takeover under a different owner is a known supply-chain vector), or the account is compromised, the resolver either fails or later resolves attacker-controlled content into a workload that already has secrets attached.
    Remediation: Do not merge with the personal-fork pin. Restore https://github.com/conforma/e2e-tests.git once feat: add e2e test coverage for the ITS pipeline e2e-tests#12 lands and pin both revisions to the merged upstream SHA.

  • [supply-chain-unmerged-dependency-pin] .tekton/cli-its-pull-request.yaml:33 — Prior finding preserved with updated SHA. Both params.revision (line 33) and pipelineRef.params[revision] (line 57) pin to 4bbba993..., which per the PR body is HEAD of the unmerged upstream PR feat: add e2e test coverage for the ITS pipeline e2e-tests#12. If that PR is squash-merged (GitHub default), the merge-commit SHA will differ and both pins reference an orphan commit that only exists in the personal fork.
    Remediation: Block merge until feat: add e2e test coverage for the ITS pipeline e2e-tests#12 is merged to main, then repin both fields to the upstream merge-commit SHA.

Medium

  • [merge-gate-absent] .tekton/cli-its-pull-request.yaml:31 — The fork URL, unmerged SHA, and debug bundle tag issues are all currently guarded only by draft status and a reviewer's memory. No automated CI check rejects .tekton/*.yaml files that reference non-canonical URLs or non-existent bundle tags.
    Remediation: Before lifting draft, replace the dheerajodha references. Consider adding a repo-level lint (a policy rule or a CI step) that rejects .tekton/*.yaml referencing repos outside conforma/*, and a check that resolves bundle tags in pipelines/**.

  • [fork-controlled-code-with-secrets] .tekton/cli-its-pull-request.yaml:16 — Downgraded from prior high. The CEL author_association allowlist [MEMBER, OWNER, COLLABORATOR] narrows exposure vs. an unrestricted trigger, but residual concerns remain: (a) COLLABORATOR is granted by outside-collaborator invites and is broader than write-required; a compromised or rogue COLLABORATOR account can still trigger. (b) The trigger fetches the ITS pipeline body from {{source_url}}/{{revision}} (the PR head fork) while the workload runs under konflux-integration-runner with konflux-test-infra and mapt-kind-secret in scope; whether those secrets are visible to a fork-supplied pipeline body depends on the runner's own sandbox semantics. (c) The pathChanged filter includes .tekton/cli-its-pull-request.yaml itself, so a matching PR can modify its own trigger. (d) The PR body notes PaC-level authorization is the primary control — that dependency should be documented as a hard prerequisite, not an aside.
    Remediation: Prefer restricting its-pipeline-repo-url to a trusted upstream and copying only the pipeline-under-test file into the workspace, or narrow allowed associations (drop COLLABORATOR unless required). Document the PaC-level approver policy as a hard prerequisite in the file header.

  • [cel-dead-branch] .tekton/cli-its-pull-request.yaml:17 — The top-level guard is event == "pull_request" (line 13), then ((body.pull_request.author_association in ...) || (body.comment.author_association in ...)) (lines 15-18). GitHub pull_request webhook payloads do not include body.comment — that field lives on issue_comment events. So under the required guard, has(body.comment) is always false and the ChatOps clause on lines 17-18 is unreachable. The inline comment on lines 11-12 ("ChatOps events check the approving commenter") implies ChatOps is supported; behavior contradicts.
    Remediation: Either drop the body.comment clause (and the accompanying comment) so intent matches behavior, or change the top-level guard to (event == "pull_request" || event == "issue_comment") so the ChatOps branch is actually reachable. Verify against PaC docs before relying on this branch.

Low

  • [supply-chain-tag-squat] pipelines/enterprise-contract/0.1/enterprise-contract.yaml:167 — Because the tag :ec-1943-deliberately-missing-round2 currently does not resolve, if this file merges as-is a later actor with push rights to quay.io/conforma/tekton-task could create that tag with arbitrary content and every downstream consumer would silently pick it up. Low probability given a controlled registry, but a real future-tense supply-chain concern distinct from today's resolve-failure symptom.
    Remediation: Same as the critical finding at this line: restore :konflux (or use a digest pin so an ephemeral tag cannot be introduced later).

  • [api-shape] .tekton/cli-its-pull-request.yaml:33 — The SHA 4bbba993... appears twice (lines 33 and 57) with an inline comment on line 50 acknowledging they must stay coupled. A YAML anchor / alias would express the coupling structurally and avoid silent drift if one copy is updated and the other is not.
    Remediation: Introduce a YAML anchor on the first revision value and alias it at the second occurrence.

  • [trigger-coverage-gap] .tekton/cli-its-pull-request.yaml:19 — pathChanged() only fires on pipelines/enterprise-contract/** or this file. Changes to underlying task sources (e.g., tasks/verify-enterprise-contract/**) or Makefile/CLI code paths that ultimately shape the built bundle will not trigger this ITS run. Informational: this is a new job, so not a regression; worth confirming the scope is intentional.

  • [param-propagation] .tekton/cli-its-pull-request.yaml:42 — its-pipeline-repo-url uses {{source_url}} and its-pipeline-revision uses {{revision}}, so for fork PRs the ITS runner fetches the pipeline-under-test from the contributor's fork at PR head. This is correct for the stated purpose, but the ITS run will fail for any PR whose fork is private or unreachable. Informational.

  • [missing-authorization] .tekton/cli-its-pull-request.yaml:1 — The PR references EC-1943 (Jira, external) and depends on feat: add e2e test coverage for the ITS pipeline e2e-tests#12 (cross-repo). No linked issue in conforma/cli exists to serve as an authorization record within this repo's public history.
    Remediation: Open a tracking issue in conforma/cli mirroring EC-1943 and link it from the PR.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (4)

Review

Findings

High

  • [supply-chain / unmerged-dependency-pin] .tekton/cli-its-pull-request.yaml:50 — Both spec.params[revision] (line 26) and spec.pipelineRef.params[revision] (line 50) pin the runner and the ITS pipeline resolver to conforma/e2e-tests SHA 715c96ced8341ce10f5ab5b800ddcdec8b3d9e79, which is the HEAD of the still-open PR feat: add e2e test coverage for the ITS pipeline e2e-tests#12. That commit has not landed on the e2e-tests main branch, so the pipeline being executed here has not cleared its own repo's review/merge gate. If Acceptance tests #12 is squash-merged (GitHub's default), the resulting merge commit will have a different SHA and both pins will silently reference an orphaned commit. The inline comment on line 43 claims the revision is "reviewed", but the reviewed gate for e2e-tests is merge to main.
    Remediation: Block merge until feat: add e2e test coverage for the ITS pipeline e2e-tests#12 is merged to main, then update both revision values (line 26 and line 50) to the resulting upstream merge-commit SHA. The PR body already flags this; keep the PR in draft until the dependency lands.

  • [fork-controlled-code-with-secrets] .tekton/cli-its-pull-request.yaml:38 — Params its-pipeline-repo-url: '{{source_url}}' (line 36) and its-pipeline-revision: '{{revision}}' (line 38) cause the runner to fetch and execute an ITS pipeline definition drawn from the PR's source repo/revision. The CEL trigger (pipelinesascode.tekton.dev/on-cel-expression, lines 11–14) only gates on event == "pull_request" and target_branch == "main"; there is no author_association, org-membership, or /ok-to-test guard expressed in this file. A fork-authored PR that touches pipelines/enterprise-contract/** or this trigger file will therefore, once run per the PaC Repository CR policy, cause fork-controlled YAML to be interpreted by the runner in namespace rhtap-contract-tenant under service account konflux-integration-runner with konflux-test-infra (registry creds) and mapt-kind-secret (AWS creds) mounted. Protection today rests entirely on the out-of-band PaC approver gate — the workflow itself does not encode that requirement. This is materially different from the sibling cli-main-pull-request.yaml, which passes {{source_url}}/{{revision}} only to build tasks that consume it as source-to-compile, not as pipeline definition to execute.
    Remediation: Pick one or more of: (a) restrict its-pipeline-repo-url / its-pipeline-revision to the trusted upstream (base repo / base ref) rather than the PR's source; (b) tighten the CEL to require a trusted actor, e.g. body.pull_request.author_association in ['MEMBER','OWNER','COLLABORATOR'], so fork PRs cannot auto-run; or (c) explicitly document and enforce the PaC-level approver gate (/ok-to-test required for fork PRs) on this Repository CR and confirm the setting is enabled. Consider also removing AWS/registry secrets from this PR-triggered variant if they are not needed for the ITS pipeline schema/lint checks it is intended to run.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

fullsend-ai-review[bot]

This comment was marked as outdated.

@dheerajodha

Copy link
Copy Markdown
Contributor Author

/retest

@codecov

codecov Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
acceptance 54.51% <ø> (ø)
generative 12.25% <ø> (ø)
integration 23.56% <ø> (ø)
unit 72.24% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🤖 Review · ⚠️ Cancelled · Started 1:30 PM UTC · Ended 1:38 PM UTC

Commit: a71cdb5 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🤖 Review · ⚠️ Cancelled · Started 1:40 PM UTC · Ended 1:44 PM UTC

Commit: 1640d50 · View workflow run →

@dheerajodha

Copy link
Copy Markdown
Contributor Author

/retest

@red-hat-konflux

Copy link
Copy Markdown
Contributor

Caution

There are some errors in your PipelineRun template.

PipelineRun Error
cli-its-on-pull-request CEL expression evaluation error: expression "event == \"pull_request\" && target_branch == \"main\" &&\nbody.pull_request.author_association in [\"MEMBER\", \"OWNER\", \"COLLABORATOR\"] &&\n(\"pipelines/enterprise-contract/**\".pathChanged() ||\n \".tekton/cli-its-pull-request.yaml\".pathChanged())\n" failed to evaluate: no such key: pull_request

@github-actions github-actions Bot added size: M and removed size: S labels Sep 24, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:46 PM UTC · Completed 1:57 PM UTC

Commit: 0a5ce00 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.89

fullsend-ai-review[bot]

This comment was marked as outdated.

@github-actions github-actions Bot added size: S and removed size: M labels Sep 24, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:02 PM UTC · Completed 2:12 PM UTC

Commit: b698772 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.40

@fullsend-ai-review fullsend-ai-review Bot added risk/moderate PR risk: moderate and removed risk/low PR risk: low labels Sep 24, 2026
fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 2:48 PM UTC · Completed 2:58 PM UTC

Commit: 455530c · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.92

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🤖 Review · ⚠️ Cancelled · Started 12:06 PM UTC · Ended 12:09 PM UTC

Commit: 6ead7e4 · View workflow run →

@dheerajodha
dheerajodha marked this pull request as ready for review September 28, 2026 12:08
@dheerajodha
dheerajodha requested a review from a team as a code owner September 28, 2026 12:08
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 12:11 PM UTC · Completed 12:22 PM UTC

Commit: 6ead7e4 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.50

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

pipelinesascode.tekton.dev/max-keep-runs: "3"
pipelinesascode.tekton.dev/on-cel-expression: |
event == "pull_request" && target_branch == "main" &&
("pipelines/enterprise-contract/**".pathChanged() ||

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] fail-open-authorization

The CEL trigger (lines 11-14) gates only on event == "pull_request", target_branch == "main", and pathChanged() over pipelines/enterprise-contract/** or .tekton/cli-its-pull-request.yaml itself. There is no author_association check and no ok-to-test label check — trust is delegated entirely to Pipelines-as-Code tenant ACLs. Amplifying facts verified against the file: (a) the CEL's pathChanged() clause at line 14 matches this file itself, so a fork PR editing it widens its own trigger surface; (b) pipelineRef (lines 43-51) resolves the pipeline body via the git resolver from a URL+revision pair currently pointing at a personal fork (line 47), meaning fork-controlled pipeline YAML would execute under serviceAccountName: konflux-integration-runner (line 53) with konflux-test-infra (line 30) and mapt-kind-secret (lines 32, 34) in scope. PaC's default fork-PR policy typically requires an owner/collaborator /ok-to-test — that mitigation is external and unverifiable from the diff.

Suggested fix: Either (a) add an explicit CEL guard for trusted actors (e.g., pipelines_as_code.author_association in ["OWNER","MEMBER","COLLABORATOR"] or a hasLabel("ok-to-test") gate) so the trust posture is expressed in-tree, or (b) document the deployed tenant PaC Repository CR trust policy as a hard prerequisite. Independently, pin pipelineRef.url/revision (lines 47, 49) to a canonical conforma/* repository+SHA so fork-authored pipeline bodies cannot execute with the mounted secrets.

spec:
params:
- name: git-url
value: https://github.com/dheerajodha/conforma-e2e-tests.git

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] unpinned-external-source

Both spec.params (git-url line 24, revision line 26) and pipelineRef (url line 47, revision line 49) reference the personal contributor fork https://github.com/dheerajodha/conforma-e2e-tests.git pinned to 4bbba993a3b44eec5debb89fbc4f8bd1c8d0503d. Per the PR body, upstream dependency conforma/e2e-tests#12 is unmerged. Risks: (a) supply chain — the personal fork can be deleted, renamed, force-pushed, or account-compromised, and its content is resolved into a PipelineRun that mounts konflux-test-infra (line 30) and mapt-kind-secret (lines 32, 34) under konflux-integration-runner (line 53); (b) SHA-orphan — if conforma/e2e-tests#12 is squash-merged (GitHub default), the merge-commit SHA will differ from 4bbba99..., which will then exist only in the personal fork; (c) governance — a shared .tekton/ PipelineRun on main should reference the canonical org repository.

Suggested fix: Block merge until conforma/e2e-tests#12 lands. Then repoint both git-url (line 24) and pipelineRef.url (line 47) to https://github.com/conforma/e2e-tests.git, and repin both revision fields (lines 26 and 49) to the upstream merge-commit SHA.

spec:
params:
- name: git-url
value: https://github.com/dheerajodha/conforma-e2e-tests.git

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] merge-gate-absent

Process-risk observation layered on top of the unpinned-external-source finding: the PR has transitioned from draft to non-draft while the fork URL (lines 24, 47) and personal-fork SHA (lines 26, 49) remain in place, and inline reminders present in the prior revision have been removed. No repo-level automated check exists to reject .tekton/.yaml files referencing URLs outside conforma/. The only surviving warning is the PR body, which is author-controlled and dropped from git history on merge. See also: [unpinned-external-source] finding at this location.

Suggested fix: Before merging: (1) replace both dheerajodha/conforma-e2e-tests.git references with conforma/e2e-tests.git (lines 24, 47), and (2) update the pinned revisions (lines 26, 49) once conforma/e2e-tests#12 lands. Longer term, add a repo-level lint or required status check that fails when .tekton/.yaml references git URLs outside the conforma/ org.

value: mapt-kind-secret
- name: deprovision-aws-credentials-secret
value: mapt-kind-secret
- name: its-pipeline-repo-url

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] api-contract

The params sent to the resolved pipeline (its-pipeline-repo-url, its-pipeline-revision, its-pipeline-path, test-label-filter, lines 35-42) diverge from the naming used by the sibling .tekton/cli-e2e-push.yaml (custom-ec-cli-url, custom-ec-cli-revision). Correctness depends on the fork's .tekton/pipelines/conforma-e2e/pipeline.yaml at revision 4bbba993... declaring these exact param names; the referenced pipeline file lives in another repository and cannot be verified from this diff. If any name/type is mismatched, the PipelineRun will fail admission or the params will be silently ignored.

build.appstudio.redhat.com/target_branch: '{{target_branch}}'
pipelinesascode.tekton.dev/cancel-in-progress: "true"
pipelinesascode.tekton.dev/max-keep-runs: "3"
pipelinesascode.tekton.dev/on-cel-expression: |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] trigger-coverage-gap

The CEL only fires when pipelines/enterprise-contract/** or this file itself changes (lines 13-14). Changes to Task sources, Makefile, or CLI code paths that materially shape the built verify bundle will not trigger this ITS run. Informational; not a regression since this is a new job.

- name: deprovision-aws-credentials-secret
value: mapt-kind-secret
- name: its-pipeline-repo-url
value: '{{source_url}}'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] param-propagation

its-pipeline-repo-url is bound to {{source_url}} (line 36) and its-pipeline-revision to {{revision}} (line 38). For fork PRs the runner fetches the pipeline-under-test from the contributor's fork at PR head — correct for the stated intent, but runs will fail for any PR whose fork is private or unreachable by the Konflux runner service account.

@@ -0,0 +1,53 @@
apiVersion: tekton.dev/v1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] missing-authorization

The PR references EC-1943 (external Jira) and depends on conforma/e2e-tests#12 (cross-repo). No linked issue in conforma/cli exists as an authorization record in this repo's public history. Not a code defect.

Suggested fix: Open a tracking issue in conforma/cli mirroring EC-1943 and link it from the PR.

@st3penta st3penta left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm. remember to update the references to the upstream repo before merging!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk/moderate PR risk: moderate size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants