Skip to content

fix: run secret-free workflows on Dependabot PRs - #1489

Open
tt-cll wants to merge 4 commits into
mainfrom
tt/dbfixes
Open

tt-cll wants to merge 4 commits into
mainfrom
tt/dbfixes

Conversation

@tt-cll

@tt-cll tt-cll commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Description

Testing

Checklist

  • Breaking changes documented in changelog (see changelog directory)
  • Cross link related PRs (in this or other repositories)

@tt-cll
tt-cll marked this pull request as ready for review October 5, 2026 23:13
@tt-cll
tt-cll requested a review from a team as a code owner October 5, 2026 23:13
Copilot AI balanced review requested due to automatic review settings October 5, 2026 23:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Missing-secret handling can silently disable authentication and required E2E coverage on trusted and merge-queue runs.

Review effort: Balanced
Findings: 2 High severity · 2 Medium severity · 1 Low severity

Open (5)
What changed in this PR

Enables secret-free Dependabot and fork PR workflows while preserving authenticated CI for trusted runs.

Changes:

  • Adds optional GATI/ECR authentication wrappers.
  • Skips secret-dependent E2E jobs when credentials are unavailable.
  • Makes coverage comments best-effort for read-only tokens.
File Description
.github/​workflows/​test-smoke.yaml Gates secret-dependent smoke tests.
.github/​workflows/​test-cl-smoke.yaml Gates Chainlink E2E and load tests.
.github/​workflows/​test-services.yaml Uses optional local token setup.
.github/​workflows/​test-evm-integration-module.yaml Uses optional local token setup.
.github/​workflows/​test-devenv-module.yaml Uses optional local token setup.
.github/​workflows/​test-deployment-module.yaml Uses optional local token setup.
.github/​workflows/​test-coverage-report.yaml Tolerates PR-comment permission failures.
.github/​workflows/​repo-hygiene.yaml Checks out before local token setup.
.github/​workflows/​golangci-lint.yaml Checks out before local token setup.
.github/​actions/​setup-github-token/​action.yaml Adds a secret-aware GATI wrapper.
.github/​actions/​run-load-test/​action.yaml Makes load-test credentials optional.
.github/​actions/​build-devenv-docker/​action.yaml Allows unauthenticated public-image builds.
.github/​actions/​aws-ecr-auth/​action.yaml Skips ECR authentication without a role.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +116 to +126
env:
CCV_IAM_ROLE: ${{ secrets.CCV_IAM_ROLE }}
JD_REGISTRY: ${{ secrets.JD_REGISTRY }}
JD_IMAGE: ${{ secrets.JD_IMAGE }}
run: |
if [[ -n "$CCV_IAM_ROLE" && -n "$JD_REGISTRY" && -n "$JD_IMAGE" ]]; then
echo "e2e_runnable=true" >> "$GITHUB_OUTPUT"
else
echo "e2e_runnable=false" >> "$GITHUB_OUTPUT"
echo "CI secrets unavailable; e2e jobs will be skipped."
fi
Comment on lines +36 to +46
env:
CCV_IAM_ROLE: ${{ secrets.CCV_IAM_ROLE }}
JD_REGISTRY: ${{ secrets.JD_REGISTRY }}
JD_IMAGE: ${{ secrets.JD_IMAGE }}
run: |
if [[ -n "$CCV_IAM_ROLE" && -n "$JD_REGISTRY" && -n "$JD_IMAGE" ]]; then
echo "e2e_runnable=true" >> "$GITHUB_OUTPUT"
else
echo "e2e_runnable=false" >> "$GITHUB_OUTPUT"
echo "CI secrets unavailable; e2e-smoke jobs will be skipped."
fi
Comment on lines +6 to +9
role-to-assume:
description: 'IAM role to assume'
required: true
description: 'IAM role to assume. Empty skips authentication.'
required: false
default: ''
Comment on lines +42 to +45
# Empty inputs mean the run has no repo secrets (Dependabot or fork PR), so skip GATI.
- name: Setup GitHub Token
id: gati
if: inputs.aws-region != '' && inputs.aws-role-arn != '' && inputs.aws-lambda-url != ''
Comment on lines +19 to +22
jd-image:
description: 'JD Docker image'
required: true
description: 'JD Docker image. Empty (secretless runs) fails the load test; gate those jobs instead.'
required: false
default: ''
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Code coverage report:

Package main tt/dbfixes Diff
github.com/smartcontractkit/chainlink-ccv/aggregator 45.55% 45.55% +0.00%
github.com/smartcontractkit/chainlink-ccv/bootstrap 65.67% 65.67% +0.00%
github.com/smartcontractkit/chainlink-ccv/cli 54.90% 54.90% +0.00%
github.com/smartcontractkit/chainlink-ccv/cmd 41.12% 41.12% +0.00%
github.com/smartcontractkit/chainlink-ccv/common 56.46% 56.46% +0.00%
github.com/smartcontractkit/chainlink-ccv/executor 42.14% 42.14% +0.00%
github.com/smartcontractkit/chainlink-ccv/indexer 34.35% 34.36% +0.01%
github.com/smartcontractkit/chainlink-ccv/integration 62.20% 62.20% +0.00%
github.com/smartcontractkit/chainlink-ccv/internal 0.00% 0.00% +0.00%
github.com/smartcontractkit/chainlink-ccv/migration 78.70% 78.70% +0.00%
github.com/smartcontractkit/chainlink-ccv/pkg 84.62% 84.62% +0.00%
github.com/smartcontractkit/chainlink-ccv/pricer 0.00% 0.00% +0.00%
github.com/smartcontractkit/chainlink-ccv/protocol 66.31% 66.31% +0.00%
github.com/smartcontractkit/chainlink-ccv/tools 38.36% 38.36% +0.00%
github.com/smartcontractkit/chainlink-ccv/verifier 36.27% 36.27% +0.00%
Total 51.10% 51.10% +0.00%

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants