fix: security #3004
No reviewers
Labels
No labels
1week
2weeks
Failed compliance check
IP cameras
NATS
Possible security concern
Review effort 1/5
Review effort 2/5
Review effort 3/5
Review effort 4/5
Review effort 5/5
UI
aardvark
accessibility
amd64
api
arm64
auth
back-end
bgp
blog
bug
build
checkers
ci-cd
cleanup
cnpg
codex
core
dependencies
device-management
documentation
duplicate
dusk
ebpf
enhancement
eta 1d
eta 1hr
eta 3d
eta 3hr
feature
fieldsurvey
github_actions
go
good first issue
help wanted
invalid
javascript
k8s
log-collector
mapper
mtr
needs-triage
netflow
network-sweep
observability
oracle
otel
plug-in
proton
python
question
reddit
redhat
research
rperf
rperf-checker
rust
sdk
security
serviceradar-agent
serviceradar-agent-gateway
serviceradar-web
serviceradar-web-ng
siem
snmp
sysmon
topology
ubiquiti
wasm
wontfix
zen-engine
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
carverauto/serviceradar!3004
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refs/pull/3004/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Imported from GitHub pull request.
Original GitHub pull request: #2977
Original author: @mfreeman451
Original URL: https://github.com/carverauto/serviceradar/pull/2977
Original created: 2026-03-02T03:19:33Z
Original updated: 2026-03-02T03:28:43Z
Original head: carverauto/serviceradar:2976-security-fix-e2e-testingyml
Original base: staging
Original merged: 2026-03-02T03:28:41Z by @mfreeman451
IMPORTANT: Please sign the Developer Certificate of Origin
Thank you for your contribution to ServiceRadar. Please note, when contributing, the developer must include
a DCO sign-off statement indicating the DCO acceptance in one commit message. Here
is an example DCO Signed-off-by line in a commit message:
Describe your changes
Issue ticket number and link
Code checklist before requesting a review
Imported GitHub PR comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/2977#issuecomment-3981788600
Original created: 2026-03-02T03:19:43Z
Review Summary by Qodo
Secure GitHub Actions workflow with environment variables
🐞 Bug fix✨ EnhancementWalkthroughs
Description
Diagram
File Changes
1. .github/workflows/e2e-tests.yml
Security+6/-3Imported GitHub PR comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/2977#issuecomment-3981788649
Original created: 2026-03-02T03:19:44Z
Code Review by Qodo
🐞 Bugs (0)📘 Rule violations (0)📎 Requirement gaps (0)Great, no issues found!
Qodo reviewed your code and found no material issues that require reviewImported GitHub PR comment.
Original author: @qodo-code-review[bot]
Original URL: https://github.com/carverauto/serviceradar/pull/2977#issuecomment-3981791442
Original created: 2026-03-02T03:20:53Z
CI Feedback 🧐
A test triggered by this PR failed. Here is an AI-generated analysis of the failure:
Action: build
Failed stage: Configure SRQL fixture database for tests [❌]
Failed test name: ""
Failure summary:
The action failed because a required secret/env var for the test setup was missing:
- The job exited
with code 1 after printing
SRQL_TEST_DATABASE_CA_CERT secret must be configured to verify SRQLfixture TLS.(log lines 707-708). The environment showsSRQL_TEST_DATABASE_CA_CERT:is empty, so theworkflow intentionally aborts when the CA cert is not provided.
Additional issue observed during post-job cleanup (not the primary failure):
-
git submodule foreach--recursive ...failed withfatal: No url found for submodule pathswift/FieldSurvey/LocalPackages/arrow-swiftin .gitmodules(log line 718), producing a warning withexit code 128.
Relevant error logs: