Skip to content

[任务] 升级runner版本-的开发实现-runner-container-hooks部分 - #48

Open
fly333sky wants to merge 2 commits into
mainfrom
issue-2026-from-main
Open

[任务] 升级runner版本-的开发实现-runner-container-hooks部分#48
fly333sky wants to merge 2 commits into
mainfrom
issue-2026-from-main

Conversation

@fly333sky

Copy link
Copy Markdown

背景

[任务] 升级runner版本(runner-container-hooks)· 开发流水线 · 开发预览阶段(代码已推 + 预览已部署 + UT 已补;门禁/对抗由 PR CI 异步跑)

改动内容

fix(runner-container-hooks): 清除 dist 中误报密钥示例字符串,gitleaks 门禁恢复通过

  • 需求核对:升级所有 runner 至 2.337.0 已在前两轮全量完成——ascend-ci-deployment 全部 values.yaml、ci-config-helper 模板、sync-images 矩阵均已为 2.337.0;runner-container-hooks Dockerfile 基础镜像为 actions-runner:2.337.0。残留 :latest 仅为 busybox/kubectl 等非 runner sidecar 镜像,不在范围。故本轮不再做版本改动。
  • 门禁修复:packages/docker/dist/index.js:2033 JSDoc 示例 const apiToken = "abc123xyz456";(打包 @actions/core 带入的文档示例,非真实凭据,无需 revoke)替换为占位符 "***"
  • 验证:gitleaks detect --no-git 在两个子仓均 no leaks found;grep 确认无其他同类模式。
  • UT:本轮为打包产物内注释字符串改动,无逻辑变更(纯文案),按规范免 UT。

相关 Issue

resolve https://github.com/opensourceways/backlog/issues/2026

AI 使用声明

当前 PR 是否有 AI 参与:

@opensourceways-bot

Copy link
Copy Markdown

Welcome To opensourceways Community

Hey @fly333sky , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands.

Contact Guide

If you have any questions, please contact the SIG: infratructure ,
and any of the maintainers: @GeorgeCao-hw, @TangJia025, @pkking, @zhongjun2 ,
and any of the committers: @GeorgeCao-hw, @Goalina, @Hourunze1997, @JavaPythonAIForBAT, @KadenZhang3321, @LiYanghang00, @ccijunk, @drizzlezyk, @pkking, @rosecoffe, @tfhddd, @yao-xiaobai, @zhongjun2, @zkhzkhz .

@opensourceways-bot

Copy link
Copy Markdown

CLA Signature Pass

fly333sky, thanks for your pull request. All authors of the commits have signed the CLA. 👍

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedhooklib@​0.1.0N/AN/AN/AN/AN/A

View full report

@opensourceways-bot

Copy link
Copy Markdown
检查项 状态
敏感信息扫描
安全编码扫描
漏洞扫描
开源license合规扫描
UT覆盖率
开发阶段设计文档检查
流水线链接 点击跳转查看日志

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants