Skip to content

chore(ci): harden delivery pipeline permissions, input validation, and configuration parity - #6

Merged
nicolasvd merged 1 commit into
mainfrom
chore/issue-5-ci-pipeline-hardening
Sep 25, 2026
Merged

nicolasvd merged 1 commit into
mainfrom
chore/issue-5-ci-pipeline-hardening

Conversation

@nicolasvd

Copy link
Copy Markdown
Owner

Closes #5

📌 Summary

Branch: chore/issue-5-ci-pipeline-hardening → main
Type: chore(ci)
Related Issue: #5 chore(ci): harden delivery pipeline permissions, input validation, and configuration parity

  • Per-Job PoLP Permissions (C-01): Removed global contents: write. Restricted quality-gate exclusively to contents: read and pull-requests: read. Scoped contents: write strictly to release jobs (semver-release, build-and-distribute).
  • Strict SemVer Input Validation (C-02): Added early input validation requiring milestone_version to match regex ^v[0-9]+\.[0-9]+\.[0-9]+$ on manual workflow_dispatch releases, aborting immediately on malformed input.
  • Configuration Parity (C-03): Harmonized tester_groups dispatch input default and fallback to "testers, dev" to achieve 100% parity with kernel.config.json:38.
  • Gradle PR Cache Isolation (C-04): Configured cache-read-only: ${{ github.event_name == 'pull_request' }} in quality-gate to prevent PR runs from corrupting or poisoning the shared build cache.
  • Dynamic Version Fallback (C-05): Replaced hardcoded fallback release version "0.4.0" with dynamic extraction from kernel.config.json:project.version.

📂 Affected Files

File Diff Role
.github/workflows/delivery-pipeline.yml +28 -9 Per-job permissions, input validation, cache isolation, configuration parity

✅ Quality Airbag — ./scripts/quality-check.sh

Check Result
Kotlin / Java compilation ✅ 0 errors
Android Lint (debug) ✅ 0 warnings
Android Lint (release) ✅ 0 warnings
Unit tests & Screenshot tests ✅ Passed (UP-TO-DATE) · 0 failed
Guardrails test suite ✅ 18/18 passed · 0 failed
./scripts/validate-docs.sh ✅ All contracts valid & byte budgets respected

⚡ FinOps & Agent Efficiency

Metric Measurement Status
Conversation turns 2 turns ✅ Optimal (< 20)
Circuit Breaker 0 trip (max 3 iterations) ✅ Passed · No loop
Context Hygiene Clean persona transitions ✅ Compliant
Security Drift Check Zero privilege elevation ✅ Compliant

📸 UI Snapshots / Roborazzi Visual Diffs

N/A — Pure CI/CD delivery pipeline and workflow configuration changes. Zero UI or composable modifications.


Caution

Zero Auto-Merge — Explicit approval required.
This PR will NOT be merged until the author explicitly confirms: "Tu peux merger" or equivalent.
Persona 6 presents this PR link and stops. Merge is a deliberate human action.

…d configuration parity

- Restrict quality-gate job permissions to contents: read, pull-requests: read (C-01)
- Scope contents: write strictly to semver-release and build-and-distribute jobs
- Enforce strict SemVer regex validation on workflow_dispatch milestone_version (C-02)
- Harmonize tester_groups default and fallback to 'testers, dev' (C-03)
- Isolate Gradle cache on PR runs with cache-read-only (C-04)
- Read fallback release version dynamically from kernel.config.json (C-05)

Closes #5
@nicolasvd nicolasvd added the skip-release Skip APK artifact release and distribution label Sep 25, 2026
@nicolasvd
nicolasvd merged commit 285e494 into main Sep 25, 2026
3 checks passed
@nicolasvd
nicolasvd deleted the chore/issue-5-ci-pipeline-hardening branch September 25, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-release Skip APK artifact release and distribution

Projects

None yet

Development

Successfully merging this pull request may close these issues.

chore(ci): harden delivery pipeline permissions, input validation, and configuration parity

1 participant