Skip to content

Pull semgrep container from Google's Docker Hub mirror - #24

Merged
ulziibay-kernel merged 1 commit into
mainfrom
hypeship/semgrep-mirror-pull
Oct 9, 2026
Merged

ulziibay-kernel merged 1 commit into
mainfrom
hypeship/semgrep-mirror-pull

Conversation

@ulziibay-kernel

@ulziibay-kernel ulziibay-kernel commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The container.credentials block added in #23 breaks every caller that doesn't define DOCKERHUB_USERNAME / DOCKERHUB_TOKEN (e.g. kernel/cli): the expression resolves to an empty string and the runner rejects the whole reusable workflow template before the job can start:

Error: The template is not valid. kernel/security-workflows/.github/workflows/semgrep.yml@main (Line: 28, Col: 19): Unexpected value ''
(Line: 29, Col: 19): Unexpected value ''

This is a known runner limitation for empty values in the container map (actions/runner#4204). Since this workflow has ~24 consumer repos, credentials keyed on caller-side vars/secrets can't work without every repo opting in.

Instead, pull the image through Google's unauthenticated Docker Hub mirror mirror.gcr.io/semgrep/semgrep — no credentials needed, and it sidesteps the shared anonymous Docker Hub pull rate limit that motivated #23 (the same option 2 proposed in the original incident thread). Added a comment in the workflow explaining why a credentials block must not come back.

Also adds semgrep-self-test.yml following the repo's existing self-test convention: any PR touching semgrep.yml runs the scan against this repo itself, so the container pull is exercised in a real pull_request context before merge.

Testing

This PR's own self-test run exercises the fixed container pull end to end (template validation + image pull + semgrep scan). Consumer repos are unaffected otherwise — the caller-facing interface (inputs, outputs, secrets) is unchanged.


Note

Low Risk
CI-only change to container image source; caller inputs, outputs, and secrets are unchanged.

Overview
Fixes reusable Semgrep workflow consumers that were failing template validation when DOCKERHUB_USERNAME / DOCKERHUB_TOKEN were unset (empty credential values break the container map).

The scan job now uses mirror.gcr.io/semgrep/semgrep instead of Docker Hub with a credentials block, avoiding both anonymous Hub rate limits and per-repo secret requirements. Inline comments document why a credentials block must not be reintroduced.

Adds semgrep-self-test.yml, which on PRs that touch the Semgrep workflows reuses semgrep.yml so image pull and the scan run in a real pull_request context before merge.

Reviewed by Cursor Bugbot for commit f7c2745. Bugbot is set up for automated code reviews on this repo. Configure here.

The credentials block from #23 breaks callers without DOCKERHUB_USERNAME /
DOCKERHUB_TOKEN: empty values in container credentials make the runner fail
template validation with "Unexpected value ''", so every consumer's scan job
dies before it starts. The mirror needs no credentials and sidesteps the shared
anonymous Docker Hub pull rate limit that motivated #23.

Add a self-test workflow that runs the scan on PRs touching semgrep.yml.
@ulziibay-kernel
ulziibay-kernel marked this pull request as ready for review October 9, 2026 23:19
@ulziibay-kernel
ulziibay-kernel merged commit aa1be87 into main Oct 9, 2026
3 checks passed
@ulziibay-kernel
ulziibay-kernel deleted the hypeship/semgrep-mirror-pull branch October 9, 2026 23:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant