Skip to content

Comments

[DELENG-365] Add catalog workflow to use whitelisted SHA#877

Open
KostenetskyiAndrii wants to merge 1 commit intomasterfrom
DELENG-365-update-catalog-workflow
Open

[DELENG-365] Add catalog workflow to use whitelisted SHA#877
KostenetskyiAndrii wants to merge 1 commit intomasterfrom
DELENG-365-update-catalog-workflow

Conversation

@KostenetskyiAndrii
Copy link

Note: This PR creates a new catalog.yml workflow file.

Summary

Updates the catalog workflow to use the whitelisted SHA from service-catalog with proper documentation.

Changes

  • Updates docs job to use service-catalog/.github/workflows/docs-like-code.yaml@436c9e4b5ba68282956ffa169ae714827cf49bc5
  • Updates catalog-upload job to use service-catalog/.github/workflows/catalog-upload.yaml@436c9e4b5ba68282956ffa169ae714827cf49bc5
  • Adds documentation comments explaining:

Context

As part of the WIF pool migration (service-catalog PR #113), all repos using catalog workflows need to reference the whitelisted SHA. This SHA is specifically allowed in the pantheon-service-catalog WIF pool configuration for production access.

Testing

  • Workflow will use the new WIF pool: pantheon-service-catalog in project pantheon-wif
  • Authentication will work with both main and master branches
  • Secrets and GCS bucket access will use production credentials

Related

@KostenetskyiAndrii KostenetskyiAndrii requested a review from a team as a code owner February 23, 2026 14:59
@wiz-inc-b08cf2810f
Copy link

wiz-inc-b08cf2810f bot commented Feb 23, 2026

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations 1 Info
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 Info

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@KostenetskyiAndrii KostenetskyiAndrii force-pushed the DELENG-365-update-catalog-workflow branch 3 times, most recently from b5720e6 to 42d74cc Compare February 23, 2026 16:24
Creates catalog.yml to use the allowlisted SHA 436c9e4b from
service-catalog PR #113 with proper documentation.

This ensures the workflow uses the pantheon-service-catalog WIF pool
with production credentials for both main and master branches.

Ticket: DELENG-365
@KostenetskyiAndrii KostenetskyiAndrii force-pushed the DELENG-365-update-catalog-workflow branch from 42d74cc to efc025e Compare February 23, 2026 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant