Skip to content

ci: Harden workflows - #450

Merged
Techassi merged 5 commits into
stackabletech:mainfrom
Saul-STFC:CI-Hardening
Aug 24, 2026
Merged

ci: Harden workflows#450
Techassi merged 5 commits into
stackabletech:mainfrom
Saul-STFC:CI-Hardening

Conversation

@Saul-STFC

Copy link
Copy Markdown
Contributor

Description

This PR adds CI Hardening to the stackablectl repo

This addresses all warnings from Zizmor and also bumps dependency versions.

NOTE: - sigstore/cosign-installer v3.9.1 → v4.1.2 : v3+ of Cosign has breaking changes to the default signature format, i'm not sure how that affects our registry/signing setup, so cosign-release is explicitly pinned to v2.6.5 for now rather than taking the installer's new default.

See:
https://github.com/sigstore/cosign/releases/tag/v3.0.1
https://blog.sigstore.dev/cosign-3-0-available/
goharbor/harbor#22592

Definition of Done Checklist

  • Not all of these items are applicable to all PRs, the author should update this template to only leave the boxes in that are relevant
  • Please make sure all these things are done and tick the boxes

Author

  • Changes are OpenShift compatible
  • CRD changes approved
  • Helm chart can be installed and deployed operator works
  • Integration tests passed (for non trivial changes)

Reviewer

  • Code contains useful comments
  • (Integration-)Test cases added
  • Documentation added or updated
  • Changelog updated
  • Cargo.toml only contains references to git tags (not specific commits or branches)

Acceptance

  • Feature Tracker has been updated
  • Proper release label has been added

@NickLarsenNZ NickLarsenNZ moved this to Development: Waiting for Review in Stackable Engineering Aug 17, 2026
@Saul-STFC

Copy link
Copy Markdown
Contributor Author

@NickLarsenNZ @Techassi

Comment thread .github/workflows/pr_cockpit.yml Outdated
@Techassi Techassi changed the title CI: Hardening ci: Harden workflows Aug 19, 2026

@Techassi Techassi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The changes themself are fine, but I think we should use the opportunity to improve the workflows in general. That is something which is on my plate since forever, but I just didn't get around to it yet.

Comment thread .github/workflows/pr_cockpit.yml Outdated
Comment thread .github/workflows/pr_docs.yml Outdated
Comment thread .github/workflows/pr_general.yml Outdated
Comment thread .github/workflows/release_stackablectl.yml Outdated
Comment thread .github/workflows/pr_pre-commit.yml Outdated
Comment thread .github/workflows/pr_prek.yaml
Comment thread .github/workflows/pr_stackablectl.yml Outdated
Comment thread .github/workflows/release_stackablectl.yml Outdated
@Techassi Techassi moved this from Development: Waiting for Review to Development: In Review in Stackable Engineering Aug 19, 2026
@Techassi
Techassi added this pull request to the merge queue Aug 24, 2026
@Techassi Techassi moved this from Development: In Review to Development: Done in Stackable Engineering Aug 24, 2026
Merged via the queue into stackabletech:main with commit 3826326 Aug 24, 2026
7 checks passed
@lfrancke lfrancke moved this from Development: Done to Done in Stackable Engineering Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

5 participants