Skip to content

feat: pass the Wiz sensor token through shared workflows - #350

Draft
ggprod wants to merge 2 commits into
mainfrom
INFRA-4106-wiz-sensor
Draft

ggprod wants to merge 2 commits into
mainfrom
INFRA-4106-wiz-sensor

Conversation

@ggprod

@ggprod ggprod commented Oct 7, 2026

Copy link
Copy Markdown

Summary

  • Threads the optional WIZ_SENSOR_TOKEN secret into action-checkout-and-setup for INFRA-4106, the MetaMask counterpart of INFRA-4094.
  • Reusable workflows declare the secret and callers pass it through. The sensor still no-ops until the organization variable WIZ_SENSOR_ENABLED is the string true.
  • Draft until MetaMask/action-checkout-and-setup#92 is released and the v3 tag includes the wiz-sensor-token input. Actionlint will reject the new input until then.

Test plan

  • Merge only after action-checkout-and-setup v3 accepts wiz-sensor-token
  • CI on this pull request logs a Wiz skip notice, and does not start the sensor
  • Leave WIZ_SENSOR_ENABLED unset or false

Made with Cursor

INFRA-4106. The token is optional. The sensor still no-ops until WIZ_SENSOR_ENABLED is true.

Co-authored-by: Cursor <cursoragent@cursor.com>
The composite action cannot read vars, so the workflow passes the org switch in.

Co-authored-by: Cursor <cursoragent@cursor.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Every action invocation omits wiz-sensor-enabled, causing the sensor to remain disabled regardless of the organization variable.

6 open findings
What changed in this PR

Threads the optional Wiz sensor token through CI and release workflows.

Changes:

  • Declares and forwards WIZ_SENSOR_TOKEN.
  • Passes the token to checkout/setup actions.
  • Updates the changelog.
File Description
CHANGELOG.md Documents token forwarding.
.github/​workflows/​publish-release.yml Propagates the token through release jobs.
.github/​workflows/​publish-rc-docs.yml Forwards the token for RC documentation.
.github/​workflows/​publish-main-docs.yml Forwards the token for staging documentation.
.github/​workflows/​publish-docs.yml Declares and consumes the optional secret.
.github/​workflows/​main.yml Supplies the token to CI and reusable workflows.
.github/​workflows/​create-release-pr.yml Supplies the token during release preparation.
.github/​workflows/​build-lint-test.yml Declares and consumes the token across test jobs.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/build-lint-test.yml
Comment thread .github/workflows/create-release-pr.yml
Comment thread .github/workflows/main.yml
Comment thread .github/workflows/publish-docs.yml
Comment thread .github/workflows/publish-release.yml
Comment thread .github/workflows/publish-release.yml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants