fix(ci): plumb VERCEL_AUTOMATION_BYPASS_SECRET into preview-smoke + visual-diff #17

Merged
varutasu merged 4 commits from convoy/fix-vercel-deployment-protection-in-ci into main 2026-05-24 17:26:22 -04:00
2 changed files with 18 additions and 4 deletions
Showing only changes of commit b6f8688df8 - Show all commits

View file

@ -40,11 +40,20 @@ jobs:
steps:
- name: Decide
id: check
env:
# Route PR body + fork flag through env vars instead of inline
# ${{ }} interpolation. Direct ${{ github.event.pull_request.body }}
# in a shell command pastes arbitrary user-controlled text (parens,
# backticks, pipes, heredocs) directly into the script — both a
# syntax-error risk AND a shell-injection vector. Quoting the env
# vars below makes both safe.
PR_BODY: ${{ github.event.pull_request.body }}
PR_IS_FORK: ${{ github.event.pull_request.head.repo.fork }}
run: |
if [[ "${{ github.event.pull_request.head.repo.fork }}" == "true" ]]; then
if [[ "$PR_IS_FORK" == "true" ]]; then
echo "should_run=false" >> $GITHUB_OUTPUT
echo "::notice::Smoke skipped on fork PR (bypass secret unavailable to forks)"
elif echo "${{ github.event.pull_request.body }}" | grep -qE 'pipeline:.*skip.*\bsmoke\b'; then
elif echo "$PR_BODY" | grep -qE 'pipeline:.*skip.*\bsmoke\b'; then
echo "should_run=false" >> $GITHUB_OUTPUT
echo "::notice::Smoke skipped via pipeline directive"
else

View file

@ -36,11 +36,16 @@ jobs:
should_run: ${{ steps.check.outputs.should_run }}
steps:
- id: check
env:
# See preview-smoke.yml for the rationale: ${{ github.event.* }}
# inlined into shell is a syntax-error + injection vector.
PR_BODY: ${{ github.event.pull_request.body }}
PR_IS_FORK: ${{ github.event.pull_request.head.repo.fork }}
run: |
if [[ "${{ github.event.pull_request.head.repo.fork }}" == "true" ]]; then
if [[ "$PR_IS_FORK" == "true" ]]; then
echo "should_run=false" >> $GITHUB_OUTPUT
echo "::notice::Visual diff skipped on fork PR (bypass secret unavailable to forks)"
elif echo "${{ github.event.pull_request.body }}" | grep -qE 'pipeline:.*skip.*\bvisual\b'; then
elif echo "$PR_BODY" | grep -qE 'pipeline:.*skip.*\bvisual\b'; then
echo "should_run=false" >> $GITHUB_OUTPUT
echo "::notice::Visual diff skipped via pipeline directive"
else