-
Notifications
You must be signed in to change notification settings - Fork 41
[feature-flags] Bypass live check for dev and dev_website if deployed commit hash is not submitted #1728
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
…f deployed githash is unsubmitted.
Summary of ChangesHello @clincoln8, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request addresses a critical deployment issue where the Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request modifies the check_flags.sh script to handle deployments with unsubmitted git hashes for dev and dev_website environments, bypassing the live commit check if the commit is not found locally. While the script improves error message redirection to stderr and makes commit hash parsing more robust, a critical security vulnerability has been identified. The expanded regex for commit hash extraction introduces a potential argument injection vulnerability in subsequent git commands, allowing an attacker to inject git options and cause unexpected script behavior. It is strongly recommended to use the -- separator in all git commands to safely handle external input. Additionally, there is one suggestion to improve the code's conciseness and maintainability.
The current script is failing to deploy when dev or dev_website is deployed with an unsubmitted githash.
This change:
|| trueto the HTML fallback grep check for commit hash to delay pipefail exiting so that the more detailed error message is printed in the logs.Testing
Executed the script, abbreviated output contains: