adoptium / adoptium/infrastructure
Evaluate signature approvals in jenkins pipelines
- Dominant language
- Python
- Stars
- 96
- Forks
- 106
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 12
Description
Noted during the Jenkins update - we have a lot of `Signatures already approved which may have introduced a security vulnerability (recommend clearing):` messages in the jenkins script approval page.
We should look at each of those, understand it, and if desired mitigate the use in the code, or add a comment to indicate the reasoning for it. This will likely involve evaluation of things in ci-jenkins-pipelines and aqa-tests repositories.
FYI @karianna @steelhead31 since this came up in the January [jenkins upgrade](https://github.com/adoptium/infrastructure/issues/3328) call
Contributor guide
Research direction
Start in the Jenkins script approval page by reviewing each already-approved signature mentioned in the warning. Trace the corresponding uses in the ci-jenkins-pipelines and aqa-tests repositories, then determine whether each should be mitigated or documented with a rationale. Done means every relevant approval has a clear decision and the resulting code or explanation is recorded.
Written by the indexing model from the issue text.
Assessment
- Domain
- ci-cd, infrastructure, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100