fix: harden check-inspektor-gadget-pin.sh against 404/block-form/narrow-NOTE gaps (#933)
Three more issues found by the same reviewer (jnathangreeg) on
armosec/private-node-agent#548, ported here from the parallel fix landing in
that repo:
1. HTTP 404 is not a definitive "commit does not exist" answer, and hard-
failing on it contradicted this script's own stated policy of warning
(not failing) when the repo/commit can't be reached. GitHub returns 404,
not 403, for any repository the caller cannot read -- a private repo and
an unauthenticated read of a repo whose visibility just changed both land
here. Now: the compare API call sends "Authorization: Bearer $GITHUB_TOKEN"
when GITHUB_TOKEN is set (the header is omitted, not sent empty, when it
isn't -- an empty Bearer value gets GitHub to answer 401 "Bad credentials"
instead of treating the call as unauthenticated, confirmed by testing
against the real API), and only HTTP 422 is treated as the definitive
hard-fail; 404 now falls through to the existing WARN+PASS branch.
check-ig-pin.yaml passes GITHUB_TOKEN: ${{ github.token }} to the step.
2. The replace-directive regex only matched the single-line form
(`^replace <module> =>`), so consolidating this go.mod's ~10 replace
lines into a `replace ( ... )` block would make the guarded module
invisible to this script -- "nothing to check", exit 0, both signals
silently disabled. Fixed by widening the match to also recognize a bare
`<module> =>` line inside a block (optional "replace" keyword, optional
leading whitespace); the block-form line is now fully parsed the same way
as the single-line form (NOTE-comment walk-up and ancestor check both
work unchanged). As a backstop for any other go.mod shape this script
still doesn't recognize, if the guarded module string appears anywhere in
go.mod but neither form matches, the script now fails loudly instead of
silently passing.
3. Signal 1 required both the word NOTE and a second regex
(`re-?pin|merged SHA`) in the comment block above the replace line, which
common conventional phrasings failed ("do not merge", "update before
merging", "squash commit"). Since the whole comment block above this one
replace line is dedicated commentary on it, the mere presence of NOTE
(case-insensitive whole word) is already unambiguous. Dropped the second
regex.
Verification:
- 404: confirmed live against the real API with a nonexistent commit hash on
the real guarded fork (github.com/kubescape/inspektor-gadget) -- now WARNs
and PASSes. Could not produce a live 422 from GitHub's compare API (every
malformed-ref variant tried also returned 404), so the 422-hard-fails path
was verified by shimming curl to return a canned 422 response and
confirming the script's case statement takes the FAIL branch (exit 1),
while a canned 404 takes the WARN+PASS branch (exit 0).
- Block form: synthetic go.mod with a `replace ( ... )` block containing the
guarded module is now fully parsed and correctly runs the ancestor check
(PASS) rather than silently skipping it; a NOTE comment above a block-form
entry is also now correctly caught (FAIL); a go.mod where the module
string appears only in a non-directive comment now fails loudly instead of
silently passing.
- NOTE narrowing: all 3 example phrasings from the review ("do not merge",
"update before merging", "squash commit") now correctly FAIL.
- The real go.mod (single-line replace, no NOTE marker) still PASSes
normally, with and without GITHUB_TOKEN set.
Docs-exempt: CI script/workflow hardening, no product behavior change. M
Matthias Bertschy committed
851e9b6b8b766f4d5e10a8a9c2e98af3500ca5bd
Parent: 3b72c62
Committed by GitHub <noreply@github.com>
on 8/27/2026, 3:03:32 PM