Skip to content

fix(e2e): retry the re-run lookup and pass inputs to the dispatch via env - #104

Merged
rotemamsa merged 1 commit into
mainfrom
fix/e2e-rerun-retry-env
Oct 7, 2026
Merged

rotemamsa merged 1 commit into
mainfrom
fix/e2e-rerun-retry-env

Conversation

@rotemamsa

@rotemamsa rotemamsa commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Follow-up to #103, from review comments on the matching caller PRs.

Changes

  • Re-run lookup retries. On a re-run the dispatch step is skipped, so the job looks up the first attempt's receiver run by correlation ID. A re-run soon after the first attempt can still miss it, because the dispatch App token sees new runs minutes late. The lookup now retries for up to 7.5 min (15 x 30s).
  • No inline expressions in the dispatch script. Values the script used as ${{ inputs.* }} / ${{ needs.* }} / ${{ github.run_id }} are now passed through env and read as shell variables, so an input cannot inject shell code into the step that holds GH_TOKEN. The pattern predates fix(e2e): get the E2E run ID from the dispatch response #103.

Both kubescape-cli-e2e-tests.yaml and incluster-comp-pr-merged.yaml. YAML parses; no ${{ }} is left inside either dispatch script.

AI-skills: armosec-shared-rules:docs_factcheck,high-confidence-review,superpowers:systematic-debugging

… env

- Re-run lookup retries for up to 7.5 min. A re-run soon after the first
  attempt can still miss the run, since the App token sees new runs late.
- Values used in the dispatch script move from inline ${{ }} to env, so a
  workflow input cannot inject shell code into the step that holds GH_TOKEN.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Rotem Refael <rotem@armosec.io>
@rotemamsa rotemamsa added the ai-assisted Created through Armosec AI tooling (armosec-shared-rules plugin) label Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9910fb4b-56fe-4b68-9a05-888f35d7101d
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Summary:

  • License scan: failure
  • Credentials scan: failure
  • Vulnerabilities scan: failure
  • Unit test: success
  • Go linting: failure

1 similar comment
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Summary:

  • License scan: failure
  • Credentials scan: failure
  • Vulnerabilities scan: failure
  • Unit test: success
  • Go linting: failure

@rotemamsa
rotemamsa merged commit 1a631c6 into main Oct 7, 2026
12 checks passed
rotemamsa added a commit to kubescape/regolibrary that referenced this pull request Oct 7, 2026
armobot pushed a commit to kubescape/regolibrary-dev that referenced this pull request Oct 7, 2026
Re-run lookup retries, and dispatch inputs are passed via env instead of
inline expressions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Rotem Refael <rotem@armosec.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted Created through Armosec AI tooling (armosec-shared-rules plugin)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants