Skip to content

ci: avoid cache restore keys on pull requests#2154

Merged
jaydeluca merged 1 commit into
prometheus:mainfrom
zeitlinger:codex/security-hardening-cache-restore
May 29, 2026
Merged

ci: avoid cache restore keys on pull requests#2154
jaydeluca merged 1 commit into
prometheus:mainfrom
zeitlinger:codex/security-hardening-cache-restore

Conversation

@zeitlinger
Copy link
Copy Markdown
Member

Summary

Removes broad Maven cache restore-keys from workflows that run on pull requests, while keeping the exact cache key.

This is a canary remediation for the cache-security.restore-keys-on-pr finding from the draft security-hardening skill.

Validation

  • security_hardening.py detect --repo . --repo-name prometheus/client_java --modules cache-security --jsonl /tmp/client-java-cache.jsonl

Signed-off-by: Gregor Zeitlinger <gregor.zeitlinger@grafana.com>
@zeitlinger zeitlinger marked this pull request as ready for review May 29, 2026 10:11
@jaydeluca jaydeluca merged commit 23f36f5 into prometheus:main May 29, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants