Skip to content

fix(deploy): bump deployer to stop logging rendered templates - #500

Merged
DerekRoberts merged 1 commit into
mainfrom
fix/deployer-template-leak
Sep 28, 2026
Merged

DerekRoberts merged 1 commit into
mainfrom
fix/deployer-template-leak

Conversation

@DerekRoberts

@DerekRoberts DerekRoberts commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Urgent security fix: bump the OpenShift deployer to a release that no longer logs rendered templates.

Deployer versions before this wrote the fully rendered template (including Secret values) into the job environment, so it was printed in the env: header of every later step in the job. The template is JSON, which escapes characters such as &, < and >, so GitHub's secret masking did not reliably catch those values. This release keeps the rendered template in a private temp file that is always removed and never prints its contents.

Only the pin lines change.

Past workflow run logs may contain secrets. Please review them and rotate any credentials that could have been exposed.

Copilot AI balanced review requested due to automatic review settings September 28, 2026 22:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The pinned commit matches v0.3.2 and contains the documented template-leak fix.

Review effort: Balanced
Findings: None

What changed in this PR

Updates OpenShift deployment workflows to v0.3.2, preventing rendered templates and secrets from leaking into logs.

Changes:

  • Pins deployer and PR cleanup workflows to the verified v0.3.2 commit.
  • Removes all remaining references to the vulnerable version.
File Description
.github/​workflows/​.deploy.yml Updates both deployer invocations.
.github/​workflows/​pr-close.yml Updates the reusable cleanup workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@DerekRoberts DerekRoberts self-assigned this Sep 28, 2026
@DerekRoberts
DerekRoberts merged commit dd47084 into main Sep 28, 2026
21 checks passed
@DerekRoberts
DerekRoberts deleted the fix/deployer-template-leak branch September 28, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants