Skip to content

Update release workflow and CODEOWNERS - #55

Merged
securethanh merged 3 commits into
mainfrom
update-workflows-codeowners
Oct 10, 2026
Merged

securethanh merged 3 commits into
mainfrom
update-workflows-codeowners

Conversation

@timweri

@timweri timweri commented Oct 9, 2026

Copy link
Copy Markdown
Contributor
  • Pin release dependencies
  • Release is pinned by the publish environment

@timweri
timweri marked this pull request as ready for review October 10, 2026 00:06
@timweri
timweri requested a review from a team as a code owner October 10, 2026 00:06

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Accepted prerelease tags can corrupt later compose bumps, and release dependencies remain partially unpinned.

3 open findings
What changed in this PR

Hardens release workflows with environment gates and dependency pinning.

Changes:

  • Gates chart and marketplace publishing and validates release tags.
  • Pins marketplace images and verifies Crane’s checksum.
  • Simplifies repository ownership.
File Description
CODEOWNERS Assigns ownership solely to the platform team.
.github/​workflows/​helm-ccv-cell-release.yml Gates publishing and verifies tags are on main.
.github/​workflows/​helm-ccv-cell-image-bump.yml Tightens image-version validation.
.github/​workflows/​gcp-marketplace-release.yaml Pins and verifies marketplace dependencies.
marketplace/​gcp/​Dockerfile Pins the Alpine builder image.
marketplace/​gcp/​data-test/​chart-overlay/​values.yaml Adds source-image digests.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/helm-ccv-cell-image-bump.yml
Comment thread .github/workflows/helm-ccv-cell-release.yml
Comment thread marketplace/gcp/Dockerfile
@CL-Eric
CL-Eric self-requested a review October 10, 2026 01:00

@CL-Eric CL-Eric left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@securethanh
securethanh merged commit 0fb6f9f into main Oct 10, 2026
5 checks passed
@securethanh
securethanh deleted the update-workflows-codeowners branch October 10, 2026 01:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants