Skip to content

IBB security verification: CI execution context of fork-PR jobs (names-only recon, will close) - #40032

Closed
athulk-star wants to merge 1 commit into
apache:masterfrom
athulk-star:bbp-ci-verify
Closed

IBB security verification: CI execution context of fork-PR jobs (names-only recon, will close)#40032
athulk-star wants to merge 1 commit into
apache:masterfrom
athulk-star:bbp-ci-verify

Conversation

@athulk-star

Copy link
Copy Markdown

Security verification PR under the Internet Bug Bounty (apache/beam is in scope).

What this does: adds a pytest conftest that prints, to the public job log only: environment variable NAMES (no values), path-existence booleans for the kubelet gcloud volume, and metadata-service HTTP status codes. No secret values are printed, nothing is exfiltrated, no repo state is modified by the check.

Why: the pull_request_target PreCommit workflows run fork-PR code on self-hosted runners with workflow-level env (DEVELOCITY/GE_CACHE credential NAMES visible) and a kubelet gcloud config path. This PR confirms which of those are present in the untrusted execution context so the exposure can be reported accurately.

Will be closed immediately after the job log is captured. Apologies for the noise, and thank you!

@github-actions github-actions Bot added the python label Sep 5, 2026
@athulk-star

Copy link
Copy Markdown
Author

Verification complete — recon output captured (env names only, metadata status codes, no secret values accessed). Closing as promised. Report to follow via IBB. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant