Uploaded image for project: 'Calunga: Python Wheel Library'
  1. Calunga: Python Wheel Library
  2. CALUNGA-138

Limit who can kick off builds of wheels

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Normal Normal
    • GeneralAvailability
    • None
    • None
    • 3
    • False
    • Hide

      None

      Show
      None
    • False

      At the moment anyone with github account can pull the index repo, modify the packages.txt and push it which would trigger a build of wheels. This is a vulnerability that needs to be addressed.

      Some basic investigation was done in CALUNGA-125 but with the repo being public, we don't really have a way to limit who can push to the repo. We'd need to make the repo private. Alternative approaches could include checking the commit author as a part of the pipeline.

              Unassigned Unassigned
              jvulgan@redhat.com Jakub Vulgan
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: