Skip to content

Add a release cache-denial action - #769

Draft
zaniebot wants to merge 2 commits into
zb/release-cache-proxy-basefrom
zb/release-cache-proxy-action
Draft

Add a release cache-denial action#769
zaniebot wants to merge 2 commits into
zb/release-cache-proxy-basefrom
zb/release-cache-proxy-action

Conversation

@zaniebot

Copy link
Copy Markdown
Collaborator

Release jobs can consume a poisoned GitHub Actions cache through clients that do not honor ACTIONS_CACHE_MODE. Add an early-running action that rejects the legacy and v2 cache APIs while preserving artifact traffic. It handles GitHub's HTTPS endpoints and Depot's injected HTTP endpoints, checks that denial is active, and removes its temporary networking and certificate changes at the end of the job.

Linux and macOS also restrict direct connections to the resolved cache-service addresses; Linux covers local Docker-bridge traffic. Windows provides DNS-based interception without that additional firewall restriction. This is defense in depth for trusted release actions, not credential revocation or a sandbox for malicious actions. The workflow integration is separate.

@zaniebot
zaniebot changed the base branch from zb/release-cache-policy to zb/release-cache-proxy-base August 17, 2026 17:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants