GitHub
682 incident problems in GitHub environments.
먼저 읽을 가이드
추천 문제
All problems (682)
CICD-1277A containerized build works but later jobs failA pipeline with service containers and generated artifacts starts failing only on later shell-based packaging or cleanup steps.CI/CDAdvanced17 minProCICD-151A deployment freeze opens for one hour, but the delayed approval queue starts the rollout after the window closes and the policy engine revokes credentials mid-releaseEverything was approved at the right time, yet execution drifted outside the governance boundary.CI/CDAdvanced17 minProSECURITY-132A GitHub App remains installed after a repository transfer, but the new organization grant was never approved and installation tokens lose repository scopeAutomation still exists, yet the trust boundary around the repo changed in a way the app permissions did not follow.SecurityAdvanced17 minProCICD-1285A matrix release publishes the right artifacts but the production deploy reuses staging metadataA signed release pipeline shows matching artifacts and later production deploys an older or partially updated manifest.CI/CDAdvanced17 minProCICD-1299A multi-arch image promotion succeeds but arm64 pods fail laterA team adds multi-arch release support and later one architecture alone begins failing cluster admission.CI/CDAdvanced17 minProCICD-1287A private package restore works on push events but fails on pull_requestA private package restore works on push events but fails on pull_request focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. Different GitHub event types can run the same pipeline under materially different secret...CI/CDAdvanced17 minProCICD-1263A private submodule checkout worked before repository hardening but now failsCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced17 minProCICD-1268A private submodule checkout worked before repository hardening but now failsA security hardening change reduces token permissions and suddenly only private submodule checkout begins failing in CI.CI/CDAdvanced17 minProCICD-252A queued ChatOps rerun inherits stale authorization after the original release freeze window already closed during a failover rehearsalThe command looks approved from the chat log while execution happens under a no-longer-valid auth context. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced17 minProCICD-1281A reusable workflow can mint an OIDC token in one repository but fails in anotherA deployment pipeline is refactored into a shared workflow and later only one repository can no longer assume the cloud role.CI/CDAdvanced17 minProSECURITY-1232A revoked credential still keeps surfacing in alertsAfter a credential rotation, scanners continue to alert because an old downloadable debug archive still contains generated metadata from the leak window.SecurityIntermediate17 minProSECURITY-1227A revoked token keeps triggering alertsSecret rotation is complete and scanners still report findings tied to historic debug bundles or retained CI artifacts.SecurityIntermediate17 minProSECURITY-1252A rotated secret keeps alertingAfter incident response, teams still see alerts tied to an older downloadable diagnostic bundle produced during the leak window.SecurityIntermediate17 minProSECURITY-1242A rotated secret keeps triggering alertsAn incident response team rotates a secret and later keeps seeing alerts tied to an old downloadable diagnostic archive.SecurityIntermediate17 minProSECURITY-1247A rotated secret keeps triggering alertsAfter a secret rotation, teams still see alerts tied to an old downloadable artifact generated during the incident window.SecurityIntermediate17 minProCICD-1258A runner was deleted and re-registered, but jobs still bounceA team replaces a broken self-hosted runner and the new one keeps cycling between connected and unusable states.CI/CDAdvanced17 minProCICD-1271A setup-node cache step succeeds on hosted runners but hangs on one self-hosted repoA monorepo using workspaces starts failing only on one self-hosted lane after cache support is enabled.CI/CDAdvanced17 minProCICD-1318An artifact signing step succeeds and provenance verification failsA release pipeline renames or relocates packaged output between signing and promotion and later attestation checks start failing.CI/CDAdvanced17 minProCICD-132An ephemeral runner image misses the internal CA root and only private registry pulls fail after autoscaling adds new workersLegacy workers continue working, but new ones cannot trust the organization registry chain.CI/CDAdvanced17 minProCICD-011Branch protection rules exist, but the deploy workflow pushes directly to mainCovers a deployment-policy problem where code-review protection exists but the automation account becomes a bypass path.CI/CDBeginner17 minPro