Skip to content

deploy workflow can publish an arbitrary branch to production #96

Description

@Aditya30ag

Problem:

Where: .github/workflows/test_and_deploy.yml, deploy job

What's wrong

if: |
  (
    github.event_name != 'pull_request' && (
    github.ref_name == 'main' ||
    github.event_name == 'workflow_dispatch'
    )
  )

The ref_name == 'main' check is only enforced for push events. For workflow_dispatch, the inner || makes the branch check irrelevant the condition is true no matter which branch the workflow is manually run on.

trigger event_name ref_name condition
push to main push main ✅ deploy (intended)
push to other branch push other ❌ no deploy (correct)
pull_request pull_request any ❌ no deploy (correct)
workflow_dispatch on main workflow_dispatch main ✅ deploy (intended)
workflow_dispatch on any other branch workflow_dispatch other ✅ deploy bug
  • Anyone with write access who runs this workflow manually from a non-main branch (easy to do by accident the Actions "Run workflow" branch dropdown doesn't default to main) will overwrite the live public docs site (numfocus.github.io/infrastructure) with unmerged/unreviewed content, with no straightforward git-based recovery of the prior deployment.

How to verify

Trace the boolean expression by hand (see table above), or trigger workflow_dispatch on a scratch branch in a fork and observe the deploy job runs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions