From 725768783f5fa764c877c4cbfdde4900ce08b102 Mon Sep 17 00:00:00 2001 From: DevTekVE Date: Tue, 11 Jun 2024 15:47:38 +0200 Subject: [PATCH] Update release files copy command in CI pipeline The `.gitlab-ci.yml` file has been updated to directly use copy command instead of the output from release_files.py script, which was previously used in the pipeline. This change is implemented for security reasons - to validate the output and prevent exposure of unnecessary files. Warning outputs are also efficiently managed now, with the use of grep command. --- .gitlab-ci.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 97108958bc..f02236428a 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -86,7 +86,9 @@ build: - mkdir -p ${BUILD_DIR} - ls -la ${BUILD_DIR} - "echo Building Rest..." - - ./release/release_files.py | sort | uniq | rsync -vrRl --files-from=- . $BUILD_DIR/ + # The output below MUST be validated otherwise we expose files that we don't want to expose + # - ./release/release_files.py | sort | uniq | rsync -vrRl --files-from=- . $BUILD_DIR/ + - cp -pR --parents $(cat release/files_common release/files_tici | sort | uniq) $BUILD_DIR/ 2> >(grep -v 'warning:' >&2) - cd $BUILD_DIR - sed -i '/from .board.jungle import PandaJungle, PandaJungleDFU/s/^/#/' panda/__init__.py # comment panda jungle when prebuilt - scons -j$(nproc) cache_dir=${CI_DIR}/scons_cache