Vendor682 problems· 14 reviewed

GitHub

682 incident problems in GitHub environments.

All problems (682)

CICD-005Jobs waiting forever due to a self-hosted runner label mismatchJobs waiting forever (Auth and Session Failure) is a hands-on troubleshooting drill. A scenario for tracking labels, groups, and permission scope when the runner is alive but jobs are not picked up. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, recent...CI/CDIntermediate19 minProCICD-1191Private submodule checkout breaksA team copies a public submodule checkout recipe. The main repo checks out cleanly, but private submodules fail depending on whether the SSH agent was configured before or after checkout.CI/CDIntermediate22 minProSECURITY-1317A GitHub Actions secret scan starts failing only forked pull requestsA GitHub Actions secret scan starts failing only forked pull requests focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Workflow security failures are often ordering bugs, not missing secret definitions.SecurityAdvanced15 minProSECURITY-1264A secret leak alert keeps returningSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced16 minProSECURITY-1310Secret scanning alerts keep firing after rotationA team rewrites history and rotates secrets successfully, but alerts keep reappearing from what looks like a clean repository.SecurityAdvanced16 minProSECURITY-109SCIM deprovision disables the SaaS account, but a long-lived personal token still lets the former admin call the APIIdentity offboarding appears complete in the UI, yet API access remains because one token type was never linked to account lifecycle enforcement.SecurityAdvanced17 minProCICD-142A reusable workflow updates its permissions block, but the caller workflow still downgrades the token scope and deployment cannot assume the cloud roleThe shared workflow looks fixed, yet the effective identity is still too narrow because the caller constrains it further.CI/CDAdvanced18 minProCICD-102OIDC exchange fails only in reusable workflowsA shared workflow refactor succeeds for linting but deployment breaks because the federated identity provider expects a different token audience than the child workflow emits.CI/CDAdvanced18 minProCICD-113Signing verifies the tarball provenance but deployment consumes an OCI reference that was never attestedThe release report shows a verified artifact, but the runtime image came from a different reference path than the object the signing step covered.CI/CDAdvanced18 minProCICD-168A reusable workflow assumes a broader OIDC scope than the caller actually grants during a failover rehearsalThe shared logic is valid, but the effective token permissions are still narrower than the deployment step needs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-069OIDC deploy role works on push events but fails on workflow_call reuseThe repository already deploys successfully on direct pushes, but the reusable workflow path now fails because the token subject pattern no longer matches the calling context.CI/CDAdvanced20 minProSECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProCICD-008Deployments passing without verificationA scenario that narrows down the root cause, centered on designing governance that enforces the verification step before deployment approval, in the situation of deployments passing without verification because a smoke-test conditional is wrong.CI/CDAdvanced23 minProCICD-058Production environment review waits foreverThe environment requires human approval on paper, but tagged releases stall indefinitely because the reviewer and branch rules were designed only for branch-based promotion.CI/CDAdvanced24 minProCICD-029Monorepo path filter misses shared library changesMonorepo path filter misses shared library changes is a hands-on troubleshooting drill. Only some services rebuild because the path filter ignores a shared package that affects multiple deployments. GitHub Rollback and Rollout needs to be checked by narrowing scope, recent cha...CI/CDAdvanced26 minProCICD-052Reusable workflow caller changes the OIDC subject and breaks deploy role trustThe same deployment worked as a repository-local workflow, but it fails after moving into a reusable workflow because the token subject no longer matches the original trust condition.CI/CDAdvanced27 minProCICD-032OIDC subject condition mismatch denies AWS deploy role assumptionGitHub Actions reaches AWS STS, but the trust policy rejects the web identity token because the subject or audience condition no longer matches the branch and environment path.CI/CDAdvanced28 minProCICD-1575An ApplicationSet renders the new branch map and one app still deploys the old refOne Argo CD application keeps syncing the old branch after branch map cleanup.CI/CDAdvanced10 minProCICD-1595An Argo CD OCI repo works and one app still syncs the old chartOne Argo CD app keeps syncing the old chart after OCI registry cleanup.CI/CDAdvanced10 minProCICD-1605An Argo CD repo update is correct and one application still syncs the old chartOne Argo CD app still syncs the old chart after registry cleanup.CI/CDAdvanced10 minPro