Tags: codefresh-io/argo-workflows
Tags
Merge pull request #365 from codefresh-io/chore/CR-31761 chore: fix security vulnerability CVE-2025-22872
chore: upgrade actions/cache to v4.2.0 (#360) Signed-off-by: Kim <[email protected]>
Merge commit from fork * fix(api): properly authorize GET workflow fallback to archive - the authorization was accidentally removed in argoproj@f1ab5aa - also if no archived workflow is found, properly return the original error as per argoproj@ac9e2de Signed-off-by: Anton Gilgur <[email protected]> * test: add permission assertions for GET WF archived fallback - the permission suite seemed to not have previously tested this - add good, bad, and fake token checks - where "bad" is valid, but unauthorized, while "fake" is valid in format, but not corresponding to a real token Signed-off-by: Anton Gilgur <[email protected]> * fix(test): assign `goodToken` initially - these tests were relying on ordering of assignments before, i.e. 1. good 2. bad 3. bad - should just assign before each test instead for simplicity / less complexity / less mistakes Signed-off-by: Anton Gilgur <[email protected]> --------- Signed-off-by: Anton Gilgur <[email protected]> Co-authored-by: Anton Gilgur <[email protected]>
Merge commit from fork * fix(api): properly authorize GET workflow fallback to archive - the authorization was accidentally removed in argoproj@f1ab5aa - also if no archived workflow is found, properly return the original error as per argoproj@ac9e2de Signed-off-by: Anton Gilgur <[email protected]> * test: add permission assertions for GET WF archived fallback - the permission suite seemed to not have previously tested this - add good, bad, and fake token checks - where "bad" is valid, but unauthorized, while "fake" is valid in format, but not corresponding to a real token Signed-off-by: Anton Gilgur <[email protected]> * fix(test): assign `goodToken` initially - these tests were relying on ordering of assignments before, i.e. 1. good 2. bad 3. bad - should just assign before each test instead for simplicity / less complexity / less mistakes Signed-off-by: Anton Gilgur <[email protected]> --------- Signed-off-by: Anton Gilgur <[email protected]> Co-authored-by: Anton Gilgur <[email protected]>
fix: use templateName where possible else nothing (argoproj#13836) Signed-off-by: isubasinghe <[email protected]>
fix: use templateName where possible else nothing (argoproj#13836) Signed-off-by: isubasinghe <[email protected]>
PreviousNext