Vendor682 problems· 14 reviewed

GitHub

682 incident problems in GitHub environments.

All problems (682)

CICD-137Build provenance records the merge queue pseudo-ref, but the published tag points elsewhere and auditors cannot reconcile the releaseAll artifacts exist, yet traceability breaks because the build source ref and user-facing release ref diverged.CI/CDAdvanced17 minProCICD-125Git submodule authentication works during checkout, but the downstream Docker build context cannot re-fetch the private module and image creation failsThe workflow clone step succeeds, yet a later stage rebuilds context in an environment without the same credentials.CI/CDAdvanced17 minProCICD-084GitHub Environment protection waits foreverReviewers approve the release, but the gate never opens because the workflow reports status to a differently cased or aliased environment than the protected one.CI/CDAdvanced17 minProCICD-1294Parallel OIDC jobs fail sporadicallyA repository changes many workflow files at once and suddenly several OIDC-enabled jobs begin failing randomly.CI/CDAdvanced17 minProCICD-101Preview environment cleanup job deletes the release candidate namespace before smoke tests startA pull request environment vanishes moments before validation because the cleanup workflow no longer waits for the downstream smoke test status.CI/CDAdvanced17 minProCICD-1260Runner registration succeeds but later reconnects fail with access deniedRunner registration succeeds but later reconnects fail with access denied focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. A token that can register a runner is not automatically sufficient for the runner's ste...CI/CDAdvanced17 minProSECURITY-1217Secret scanning catches the token againA revoked token disappears from the repo tree but scanning keeps flagging downloads or release bundles.SecurityIntermediate17 minProCICD-118Secret-scanning allowlist suppresses detection of a real deploy key leak after the repository path pattern changedA known false positive rule is kept too broad, and once the repository layout changes it begins to hide a genuine credential leak in the new path.CI/CDAdvanced17 minProCICD-1261A cache restore step works on hosted runners but fails on a self-hosted runnerCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced18 minProCICD-1266A cache restore step works on hosted runners but fails on a self-hosted runnerA self-hosted pipeline starts failing only on cache restore or save after a containerized or sudo-based build step was introduced.CI/CDAdvanced18 minProCICD-1289A canary deploy health check stays redA canary deployment begins failing only after a cluster or auth dependency upgrade, even though application code and rollout logic are unchanged.CI/CDAdvanced18 minProCICD-1250A deployment concurrency rule exists but two production writes still overlapTeams split release and hotfix workflows and later discover both can deploy to the same target at once even though each workflow defines concurrency.CI/CDAdvanced18 minProCICD-1246A deployment preview updates successfully but one approval job still shows the previous commitA pull request preview deploy completes and reviewers still see links or status details bound to a previous commit's environment record.CI/CDAdvanced18 minProCICD-1265A Docker build pushes successfully but later pulls failCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced18 minProCICD-1270A Docker build pushes successfully but later pulls failA registry migration leaves CI green while production deploys fail or pull an unexpected image because the runtime host is still logged into the former registry.CI/CDAdvanced18 minProCICD-1238A private registry login works in setup but later restore still failsA workflow can authenticate to a private registry, but later pull operations fail only after the pipeline enters a composite helper action.CI/CDAdvanced18 minProCICD-1255A production approval exists but two deployment workflows still overlapA release workflow and a hotfix workflow both define concurrency and still deploy over one another on the same target.CI/CDAdvanced18 minProCICD-270A provenance gate compares Git tags while the published release is built from a detached worktree tarball during a failover rehearsalSource control identity and published artifact identity diverge even though both look plausible in isolation. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-477A reusable workflow signs container images correctlyA reusable workflow signs container images correctly focuses on ci-cd-release-safety and asks the reader to isolate Permission Denied in GitHub. 실무에서는 ci-cd-release-safety 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate18 minProCICD-1279A self-hosted runner appears healthy in the UI but jobs fail sporadicallyA self-hosted runner becomes flaky over time even though no single workflow change explains the instability.CI/CDAdvanced18 minPro