Skip to content

fix(buildkite): checkout trusted benchmark pipelines from main#389

Open
jcc-google wants to merge 2 commits into
vllm-project:mainfrom
jcc-google:fix/pipeline-injection-benchmark-b510375165
Open

fix(buildkite): checkout trusted benchmark pipelines from main#389
jcc-google wants to merge 2 commits into
vllm-project:mainfrom
jcc-google:fix/pipeline-injection-benchmark-b510375165

Conversation

@jcc-google

Copy link
Copy Markdown
Contributor

During PR builds, fetch origin/main and checkout the trusted version of the .buildkite/nightly-benchmarks/ directory. This ensures that any malicious modifications to the benchmark pipelines in the PR are ignored, preventing pipeline injection attacks.

BUG=b/510375165
TAG=agy
CONV=f5118c4a-3577-4dc6-a4b6-1f2abb990935

During PR builds, fetch origin/main and checkout the trusted version of
the .buildkite/nightly-benchmarks/ directory. This ensures that any
malicious modifications to the benchmark pipelines in the PR are ignored,
preventing pipeline injection attacks.

Signed-off-by: Jincheng Chen <chenjincheng@google.com>
BUG=b/510375165
TAG=agy
CONV=f5118c4a-3577-4dc6-a4b6-1f2abb990935
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant