[JIRA] (JENKINS-59845) Whitelisting of Gerrit-users/groups whose changes are built

2 views
Skip to first unread message

thomas.draebing@gmail.com (JIRA)

unread,
Oct 18, 2019, 9:35:04 AM10/18/19
to jenkinsc...@googlegroups.com
Thomas Draebing created an issue
 
Jenkins / New Feature JENKINS-59845
Whitelisting of Gerrit-users/groups whose changes are built
Issue Type: New Feature New Feature
Assignee: lucamilanesio
Components: gerrit-code-review-plugin
Created: 2019-10-18 13:34
Priority: Minor Minor
Reporter: Thomas Draebing

Building every change that is pushed to Gerrit is potentially dangerous on publicly accessible Gerrit servers, since users may add malicious code that might be executed during the build job.

As an example, the Kubernetes project solves this issue by requiring a label in each pull request that will be validated. This label can only be set by trusted contributors of the project. A similar setup would also be useful to have for changes in Gerrit. A way to do this would be to decide on the change's author and/or his/her group in Gerrit whether to trigger a build. A build of a change of a non-whitelisted user could be then triggered by a label set in Gerrit by a project maintainer.

 

This functionality should be part of this plugin and would be useful for a lot of projects.

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.13.6#713006-sha1:cc4451f)
Atlassian logo
Reply all
Reply to author
Forward
0 new messages