Skip to content

Comments

[DELENG-365] Add catalog workflow to use whitelisted SHA#530

Open
KostenetskyiAndrii wants to merge 1 commit intomasterfrom
DELENG-365-update-catalog-workflow
Open

[DELENG-365] Add catalog workflow to use whitelisted SHA#530
KostenetskyiAndrii wants to merge 1 commit intomasterfrom
DELENG-365-update-catalog-workflow

Conversation

@KostenetskyiAndrii
Copy link

Note: This PR creates a new catalog.yml workflow file.

Summary

Updates the catalog workflow to use the whitelisted SHA from service-catalog with proper documentation.

Changes

  • Updates docs job to use service-catalog/.github/workflows/docs-like-code.yaml@436c9e4b5ba68282956ffa169ae714827cf49bc5
  • Updates catalog-upload job to use service-catalog/.github/workflows/catalog-upload.yaml@436c9e4b5ba68282956ffa169ae714827cf49bc5
  • Adds documentation comments explaining:

Context

As part of the WIF pool migration (service-catalog PR #113), all repos using catalog workflows need to reference the whitelisted SHA. This SHA is specifically allowed in the pantheon-service-catalog WIF pool configuration for production access.

Testing

  • Workflow will use the new WIF pool: pantheon-service-catalog in project pantheon-wif
  • Authentication will work with both main and master branches
  • Secrets and GCS bucket access will use production credentials

Related

@KostenetskyiAndrii KostenetskyiAndrii requested a review from a team as a code owner February 23, 2026 15:18
@wiz-inc-b08cf2810f
Copy link

wiz-inc-b08cf2810f bot commented Feb 23, 2026

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations 1 Info
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 Info

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@KostenetskyiAndrii KostenetskyiAndrii force-pushed the DELENG-365-update-catalog-workflow branch 2 times, most recently from 787b161 to e166e51 Compare February 23, 2026 16:14
@djschaap
Copy link
Member

Be aware this is a PUBLIC repo that is essentially in maintenance mode. Merging changes such as this may not be advisable.

@KostenetskyiAndrii KostenetskyiAndrii force-pushed the DELENG-365-update-catalog-workflow branch 3 times, most recently from 6a056da to 676c640 Compare February 23, 2026 17:32
Creates catalog.yml to use the allowlisted SHA 436c9e4b from
service-catalog PR #113 with proper documentation.

This ensures the workflow uses the pantheon-service-catalog WIF pool
with production credentials for both main and master branches.

Ticket: DELENG-365
@KostenetskyiAndrii KostenetskyiAndrii force-pushed the DELENG-365-update-catalog-workflow branch from 676c640 to dce6114 Compare February 23, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants