adoptium / adoptium/infrastructure

Evaluate signature approvals in jenkins pipelines

Open
#3,336 0 comments 0 reactions 0 assignees View on GitHub
Jenkins security
Dominant language
Python
Stars
96
Forks
106
Avg merge
1d 16h
Merged PRs (30d)
12

Description

Noted during the Jenkins update - we have a lot of `Signatures already approved which may have introduced a security vulnerability (recommend clearing):` messages in the jenkins script approval page.

We should look at each of those, understand it, and if desired mitigate the use in the code, or add a comment to indicate the reasoning for it. This will likely involve evaluation of things in ci-jenkins-pipelines and aqa-tests repositories.

FYI @karianna @steelhead31 since this came up in the January [jenkins upgrade](https://github.com/adoptium/infrastructure/issues/3328) call

Contributor guide

Open the contributing guide

Research direction

Start in the Jenkins script approval page by reviewing each already-approved signature mentioned in the warning. Trace the corresponding uses in the ci-jenkins-pipelines and aqa-tests repositories, then determine whether each should be mitigated or documented with a rationale. Done means every relevant approval has a clear decision and the resulting code or explanation is recorded.

Written by the indexing model from the issue text.

Assessment

Domain
ci-cd, infrastructure, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.