| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Co-Authored-By: mish@e2b.dev <mish@e2b.dev>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
Sorry, something went wrong.
Co-Authored-By: mish@e2b.dev <mish@e2b.dev>
Co-Authored-By: mish@e2b.dev <mish@e2b.dev>
| group: Release-${{ github.ref }}-${{ matrix.cluster }} | ||
| cancel-in-progress: false | ||
| env: | ||
| E2B_API_KEY: ${{ secrets[matrix.api_key_secret] }} |
There was a problem hiding this comment.
Sorry, something went wrong.
| group: Release-${{ github.ref }}-${{ matrix.cluster }} | ||
| cancel-in-progress: false | ||
| env: | ||
| E2B_API_KEY: ${{ secrets[matrix.api_key_secret] }} |
There was a problem hiding this comment.
🔒 Agentic Security Review
Severity: MEDIUM
The reusable cluster-build job selects the API key with a dynamic secrets lookup (secrets[matrix.api_key_secret]). GitHub cannot statically determine which secrets that expression needs, so the runner receives every secret inherited by the called workflow. Both callers pass secrets: inherit, so the release path now exposes unused high-value credentials (PyPI, Docker Hub, version-bumper private key, Slack webhooks, and other clusters’ API keys) to this job. E2B_API_KEY is also set at job scope, so every step—including third-party actions and pip install—sees it.
Impact: Compromise of any step on a template-build runner (hijacked Action, poisoned pip dependency, or later logging of context) can read the full inherited secret set instead of a single cluster API key.
Reviewed by Cursor Security Reviewer for commit f8cb5ab. Configure here.
Sorry, something went wrong.
Co-Authored-By: mish@e2b.dev <mish@e2b.dev>
| group: Release-${{ github.ref }}-${{ matrix.cluster }} | ||
| cancel-in-progress: false | ||
| env: | ||
| E2B_API_KEY: ${{ secrets[matrix.api_key_secret] }} |
There was a problem hiding this comment.
🔒 Agentic Security Review
Severity: MEDIUM
The reusable cluster-build job selects the API key with a dynamic secrets lookup (secrets[matrix.api_key_secret]). GitHub cannot statically determine which secrets that expression needs, so the runner receives every secret inherited by the called workflow. Both callers pass secrets: inherit, so the release path now delivers unused high-value credentials (PyPI, Docker Hub, version-bumper private key, Slack webhooks, and other clusters’ API keys) to this job. E2B_API_KEY is also set at job scope, so every step—including third-party actions and pip install—sees the selected cluster key.
Impact: Compromise of any step on a template-build runner (hijacked Action, poisoned pip dependency, or later logging of context) can read the full inherited secret set instead of a single cluster API key.
Reviewed by Cursor Security Reviewer for commit 6bccfc0. Configure here.
Sorry, something went wrong.
There was a problem hiding this comment.
devin/1788791816-build-templates-all-clusters
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Summary
code-interpreter-v1 is now built on every production cluster — foxtrot, juliett and tango — instead of foxtrot only. Clusters are separate tenancies with separate template registries, so a template built on one does not exist on the others.
The build moves into a reusable workflow, build_prod_template_clusters.yml (workflow_call: target, skip_cache; secrets: inherit), which holds the cluster map once and fans out as a matrix:
plan -> jq: [{cluster, domain, api_key_secret, production}] filtered by `target` build-template -> strategy.matrix.include: fromJSON(needs.plan.outputs.matrix) env: E2B_API_KEY: ${{ secrets[matrix.api_key_secret] }}, E2B_DOMAIN: ${{ matrix.domain }}Companion PR for the desktop template: e2b-dev/desktop#260.
Link to Devin session: https://app.devin.ai/sessions/164235e15a6f4e30bbdc3907d388fbc5
Open in Devin Desktop: https://app.devin.ai/desktop/session/164235e15a6f4e30bbdc3907d388fbc5?variant=devin
Requested by: @mishushakov