Skip to content

Use main in the re-usable workflows from opensearch-build repo - #5805

Open
peterzhuamazon wants to merge 1 commit into
opensearch-project:mainfrom
peterzhuamazon:update-sql-id
Open

peterzhuamazon wants to merge 1 commit into
opensearch-project:mainfrom
peterzhuamazon:update-sql-id

Conversation

@peterzhuamazon

Copy link
Copy Markdown
Member

Description

Use main in the re-usable workflows from opensearch-build repo

Related Issues

https://github.com/opensearch-project/sql/actions/runs/36042567913/job/107778169273?pr=5789

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

Signed-off-by: Peter Zhu <zhujiaxi@amazon.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 54fcf16.

PathLineSeverityDescription
.github/workflows/analytics-engine-compat.yml18highPinned commit SHA (761e093b8c1349cc07f21c1d681d3b30bf9e1999) replaced with mutable branch ref '@main' for external reusable workflow 'opensearch-project/opensearch-build'. This removes supply chain protection: any future compromise of the upstream repo's main branch will execute arbitrary code in this CI/CD pipeline.
.github/workflows/integ-tests-with-security.yml16highPinned commit SHA replaced with mutable '@main' ref for external reusable workflow 'opensearch-project/opensearch-build/get-ci-image-tag.yml'. Unpinned external workflow references are a known supply chain attack vector.
.github/workflows/issue-dedupe.yml26highTwo pinned SHA references replaced with '@main' for external reusable workflows 'issue-dedupe-detect.yml' and 'issue-dedupe-autoclose.yml' from opensearch-project/opensearch-build. Both now resolve dynamically at runtime, allowing upstream changes to affect this pipeline without review.
.github/workflows/pr_review.yml9highTwo pinned SHA references replaced with '@main' for 'code-diff-analyzer.yml' and 'code-diff-reviewer.yml' from opensearch-project/opensearch-build. These workflows run on pull requests with 'id-token: write' (OIDC) and 'pull-requests: write' permissions, making a supply chain compromise here especially impactful.
.github/workflows/sql-pitest.yml15highPinned commit SHA replaced with mutable '@main' ref for external reusable workflow 'opensearch-project/opensearch-build/get-ci-image-tag.yml'. Removes immutability guarantee for this CI dependency.
.github/workflows/sql-test-and-build-workflow.yml23highPinned commit SHA replaced with mutable '@main' ref for external reusable workflow 'opensearch-project/opensearch-build/get-ci-image-tag.yml'. Build and test pipelines are high-value targets for supply chain attacks.
.github/workflows/sql-test-workflow.yml15highPinned commit SHA replaced with mutable '@main' ref for external reusable workflow 'opensearch-project/opensearch-build/get-ci-image-tag.yml'. Removes supply chain protection across all 7 workflow files in a coordinated pattern.

The table above displays the top 10 most important findings.

Total: 7 | Critical: 0 | High: 7 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@peterzhuamazon peterzhuamazon added backport 3.8 skip-changelog skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis. labels Sep 24, 2026
@peterzhuamazon

Copy link
Copy Markdown
Member Author

Expected bump.

@github-actions

Copy link
Copy Markdown
Contributor

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

🧪 No relevant tests
🔒 No security concerns identified
✅ No TODO sections
🔀 No multiple PR themes
⚡ Recommended focus areas for review

Stability Risk

Switching from a pinned commit SHA to @main removes version stability. The main branch can introduce breaking changes at any time, potentially causing workflow failures without warning. This affects all workflow files in this PR. If the opensearch-build repository's main branch introduces incompatible changes, all these workflows will break simultaneously.

uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@main

@github-actions

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion                                                                                                                                    Impact
Possible issue
Pin workflow to stable version

Using @main for reusable workflows introduces instability as the main branch can
change unexpectedly, potentially breaking your CI/CD pipeline. Pin to a specific
commit SHA or use a stable release tag to ensure reproducible builds and prevent
unexpected failures.

.github/workflows/analytics-engine-compat.yml [18]

-uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@main
+uses: opensearch-project/opensearch-build/.github/workflows/get-ci-image-tag.yml@v1.0.0 # or a specific commit SHA
Suggestion importance[1-10]: 7

__

Why: The suggestion correctly identifies a stability concern with using @main for reusable workflows, as it can lead to unexpected changes. However, this is a trade-off decision between stability and getting latest updates, and the PR intentionally changes from a pinned SHA to @main across all workflows, suggesting this is a deliberate architectural choice rather than an oversight.

Medium

@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 63.23%. Comparing base (5953571) to head (54fcf16).

❌ Your project check has failed because the head coverage (63.23%) is below the target coverage (99.00%). You can increase the head coverage or adjust the target coverage.

Additional details and impacted files
@@            Coverage Diff            @@
##               main    #5805   +/-   ##
=========================================
  Coverage     63.23%   63.23%           
  Complexity     8823     8823           
=========================================
  Files           938      938           
  Lines         40236    40236           
  Branches       4537     4537           
=========================================
  Hits          25445    25445           
  Misses        13966    13966           
  Partials        825      825           
Flag Coverage Δ
sql-engine 63.23% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport 3.8 enhancement New feature or request skip-changelog skip-diff-analyzer Maintainer to skip code-diff-analyzer check, after reviewing issues in AI analysis.

Projects

Status: 👀 In Review
Status: In review

Development

Successfully merging this pull request may close these issues.

3 participants