Skip to content

docs(audit): record Round 7 - actions pinned to SHAs (PR #81) - #82

Merged
JOY (JOY) merged 1 commit into
devfrom
docs/audit-round7-md28
Sep 19, 2026
Merged

JOY (JOY) merged 1 commit into
devfrom
docs/audit-round7-md28

Conversation

@JOY

Copy link
Copy Markdown

Records MD-28 (fork-chain portion) as fixed in Round 7: all external actions in the fork's CI/deploy chain pinned to in-major release SHAs with version comments.

🤖 Generated by ZCode

@coderabbitai

coderabbitai Bot commented Sep 19, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 33e2e709-3214-401a-9e5e-77230317ded2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the audit report HTML file to document the fixes completed in Round 7 (PR #81), specifically marking MD-28 (pinning action SHAs in the fork chain) as fixed and updating the status notes. The review feedback points out that several items in the remaining (TAIL) list (such as MD-30, LO-04, LO-05, and parts of HI-12) are now outdated or redundant and should be cleaned up to accurately reflect the current state.

<tr><td><span class="badge b-crit">ĐÃ FIX (Round 7 - 2026-09-19, PR #81)</span></td><td>MD-28 (phần fork chain)</td><td>Mọi action ngoài (checkout, cache, cache/restore, setup-node, docker setup-buildx/login/build-push) trong chuỗi CI + deploy của fork được pin theo commit SHA của bản release mới nhất trong cùng major (không jump major), kèm comment version để nâng cấp sau. Workflows upstream khác (labeler, cache-clean v.v.) không thuộc chuỗi chạy của fork nên giữ nguyên chờ sync.<code>deploy-docker</code>/<code>deploy-api-v2-docker</code> (giữ packages:write) không còn tag di động nào.</td></tr>
<tr><td><span class="badge b-med">CHỜ QUYẾT ĐỊNH</span></td><td>HI-13, HI-14, HI-16, HI-10</td><td>HI-13: 61 migrations cần biết DB prod dùng schema nào (lưu ý: upstream đã đóng source 2026-04 nên áp lực sync giảm). HI-14: wire workflows dispatcher là quyết định feature - tham khảo Cal.com Workflows 2.0 (v6.9) trong report feature-gap cùng ngày. HI-16: branding hardcode - giờ upstream đóng source nên việc giữ branding riêng có chủ đích là phương án hợp lý, cần chốt. HI-10: bật crons cần cấu hình secrets riêng (CRON_SECRET v.v.) trước. Khi deploy: rotate secret Supabase + env mới (CRON_SECRET, OIDC_*, BREVO/CROVE/DOS_SYNC_WEBHOOK_SECRET, DATABASE_SSL_REJECT_UNAUTHORIZED=false nếu pooler cần) + prisma migrate deploy</td></tr>
<tr><td><span class="badge b-low">CÒN LẠI (TAIL)</span></td><td>Docker phần dở + perf/cosmetic</td><td>HI-12 phần còn lại (pin actions theo SHA - trùng MD-28; turbo prune để bỏ dev deps khỏi image), LO-13 phần dở (prisma/.env symlink, pin trigger.dev), MD-16…22 (frontend perf), MD-27/28 (CI supply-chain hygiene), MD-30 (Stripe png), MD-31/32 (latent), LO-01/04/05/06/07 (một phần)/08/09/11/14</td></tr>
<tr><td><span class="badge b-low">CÒN LẠI (TAIL)</span></td><td>Docker phần dở + perf/cosmetic</td><td>HI-12 phần còn lại (pin actions theo SHA - trùng MD-28; turbo prune để bỏ dev deps khỏi image), LO-13 phần dở (prisma/.env symlink, pin trigger.dev), MD-16…22 (frontend perf), MD-27 (CI immutable installs), MD-30 đã xử lý ở Round 6, MD-31/32 (latent), LO-01/04/05/06/07 (một phần)/08/09/11/14</td></tr>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Several items in the remaining (TAIL) list are outdated or redundant:

  1. MD-30 is already marked as fixed in Round 6, so it should be completely removed from the remaining list instead of having a note.
  2. LO-04 and LO-05 were also fixed in Round 6, so they should be removed from the LO-01/04/05... list.
  3. Since MD-28 (pin actions to SHA) is now fixed in Round 7, the corresponding part of HI-12 is also resolved and can be removed from the description.
Suggested change
<tr><td><span class="badge b-low">CÒN LẠI (TAIL)</span></td><td>Docker phần dở + perf/cosmetic</td><td>HI-12 phần còn lại (pin actions theo SHA - trùng MD-28; turbo prune để bỏ dev deps khỏi image), LO-13 phần dở (prisma/.env symlink, pin trigger.dev), MD-16…22 (frontend perf), MD-27 (CI immutable installs), MD-30 đã xử lý ở Round 6, MD-31/32 (latent), LO-01/04/05/06/07 (một phần)/08/09/11/14</td></tr>
<tr><td><span class="badge b-low">CÒN LẠI (TAIL)</span></td><td>Docker phần dở + perf/cosmetic</td><td>HI-12 phần còn lại (turbo prune để bỏ dev deps khỏi image), LO-13 phần dở (prisma/.env symlink, pin trigger.dev), MD-16…22 (frontend perf), MD-27 (CI immutable installs), MD-31/32 (latent), LO-01/06/07 (một phần)/08/09/11/14</td></tr>

@JOY
JOY (JOY) merged commit fd1540f into dev Sep 19, 2026
11 checks passed
@JOY
JOY (JOY) deleted the docs/audit-round7-md28 branch September 19, 2026 05:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant