Skip to content

test(ci): Retest security review workflow - #3298

Closed
WesleyRosenblum wants to merge 1 commit into
WesleyRosenblum/securityreviewerfrom
WesleyRosenblum/securityreviewer-retest
Closed

test(ci): Retest security review workflow#3298
WesleyRosenblum wants to merge 1 commit into
WesleyRosenblum/securityreviewerfrom
WesleyRosenblum/securityreviewer-retest

Conversation

@WesleyRosenblum

@WesleyRosenblum WesleyRosenblum commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Purpose

Controlled retest for #3280 after deploying the CodeBuild service-role permission from CR-301784045.

Expected behavior

  • Author permission and pinned SHA preflight succeed.
  • GitHub OIDC assumes the project-scoped launcher role.
  • CodeBuild retrieves its existing GitHub source credential and proceeds beyond DOWNLOAD_SOURCE.
  • The reviewer exports a verdict and reviewed SHA.
  • A commit-specific status is published.

This PR is test-only and must not be merged.

Create a harmless upstream child PR to verify the deployed CodeBuild source credential permission.
@WesleyRosenblum

Copy link
Copy Markdown
Contributor Author

Controlled retest passed end-to-end after deploying CR-301784045. CodeBuild SecurityReview-s2n-quic:ab1bc8fb-bd8d-464d-b954-89ac84303957 completed with PASS for c9d4abb, and the commit-specific security-review / report status was published successfully. Closing this test-only PR without merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant