Skip to content

fix[backend](pipelines): fixed pipeline edition error - #2818

Merged
AlexSanchez-bit merged 2 commits into
release/v12.0.0from
backlog/v12_pipeline_edition
Oct 1, 2026
Merged

AlexSanchez-bit merged 2 commits into
release/v12.0.0from
backlog/v12_pipeline_edition

Conversation

@AlexSanchez-bit

Copy link
Copy Markdown
Contributor

No description provided.

@AlexSanchez-bit AlexSanchez-bit linked an issue Oct 1, 2026 that may be closed by this pull request
2 of 3 tasks
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🛑 AI review — Sensitive area, extra care recommended

This PR touches critical paths or introduces changes the model cannot judge with sufficient confidence. Review carefully before merging.

🛑 architecture (silas-1.7-pro) — high/critical — please review

Summary: Removes tenant-scoped path and content handling in PipelineStore.Update, risking cross-tenant updates and breaking existing persisted pipeline locations.

  • high backend/modules/eventprocessing/repository/pipeline_store.go:200 — Update no longer rewrites relPath to the tenant-specific storage path or injects tenantId into content, while Create likely still does. This changes persisted layout, can fail to update existing tenant pipelines, and may allow cross-tenant mutation. Restore tenant-scoped update logic or add a compatibility/migration path with tests.

🛑 bugs (silas-1.7-pro) — high/critical — please review

Summary: Update no longer rewrites tenant-specific paths or injects tenantId, so tenant updates may write to the wrong file and leave tenant pipelines stale.

  • high backend/modules/eventprocessing/repository/pipeline_store.go:199 — The removed tenant handling means Update(relPath, content, tenantId) no longer rewrites relPath to the tenant-specific path or injects tenantId into content. If Create uses tenant-specific paths, calling Update with a non-empty tenantId will update the base path instead, leaving the tenant-specific pipeline stale or causing cross-tenant inconsistency. Reproduce by creating a tenant pipeline, then updating it with tenantId and inspecting the tenant-specific file.

🛑 security (silas-1.7-pro) — high/critical — please review

Summary: Removal of tenant-scoped path rewriting in PipelineStore.Update allows cross-tenant pipeline updates and possible path traversal.

  • high backend/modules/eventprocessing/repository/pipeline_store.go:199 — Update no longer rewrites relPath into a tenant-scoped path or injects the tenant ID into content, allowing a tenant to update another tenant's or global pipeline file and potentially traverse paths. Restore tenant isolation and validate relPath.

🔴 go-deps — pending updates

🔍 Discovered 30 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - google.golang.org/api: v0.299.0 → v0.300.0

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.1 → v1.89.0

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.2
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2

  📁 ./backend:
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/threatwinds/go-sdk: v1.1.27-0.20260819160318-c56c250bc585 → v1.1.36
     - google.golang.org/api: v0.299.0 → v0.300.0

  📁 ./tools/rulecheck:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./log-input:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.28 → v1.1.36

  📁 ./collectors/utmstack:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/forwarder:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

  📁 ./collectors/as400:
     - github.com/threatwinds/go-sdk: v1.1.31 → v1.1.36

❌ Please update dependencies before merging.

@AlexSanchez-bit
AlexSanchez-bit merged commit ebc5667 into release/v12.0.0 Oct 1, 2026
1 check passed
@AlexSanchez-bit
AlexSanchez-bit deleted the backlog/v12_pipeline_edition branch October 1, 2026 23:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

custom pipeline edition throwing not found error

1 participant