Skip to content

🔄 synced file(s) with nextcloud/android-config - #6758

Open
nextcloud-android-bot wants to merge 1 commit into
masterfrom
repo-sync/android-config/master
Open

nextcloud-android-bot wants to merge 1 commit into
masterfrom
repo-sync/android-config/master

Conversation

@nextcloud-android-bot

@nextcloud-android-bot nextcloud-android-bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

synced local file(s) with nextcloud/android-config.

Changed files
  • synced local directory .github/workflows/ with remote directory config/workflows/

This PR was created automatically by the repo-file-sync-action workflow run #36686766041

@nextcloud-android-bot
nextcloud-android-bot force-pushed the repo-sync/android-config/master branch from 871cc29 to 0a60939 Compare September 24, 2026 07:10
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

📱 QA build

Download app-qa-debug.apk
QR code Open the QR code for this download
Commit d12983d
Version 6758
Available until 7 days after this build

The QA build installs alongside a released Nextcloud app, so you can keep
using your existing install while testing.

Downloading the file requires a GitHub account, so open this link on the
device you want to test on, or transfer the APK to it.

@nextcloud-android-bot
nextcloud-android-bot force-pushed the repo-sync/android-config/master branch 2 times, most recently from 2bf3808 to dd7e6a8 Compare September 26, 2026 07:03
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a7475276-80f1-4362-8236-4563604a3040

📥 Commits

Reviewing files that changed from the base of the PR and between 5900fab and bdf8793.

📒 Files selected for processing (1)
  • .github/workflows/codeql.yml

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The analysis and QA workflows now use ubuntu-latest-max and Java 25. The analysis workflow increases Gradle’s maximum heap from 1 GB to 6 GB. The CodeQL init and analyze actions and the Scorecard SARIF upload action now use v4.38.2. The CodeQL workflow also uses ubuntu-latest-max and Java 25.

Priority: ⬇️ Low

Merge Risk: ⚪ Minimal · up to bdf87

No demonstrated workflow failure blocks merging. CodeQL’s new runner label depends on externally managed runner configuration.

Security Architecture Review

Security architecture risk: 🔵 Low · up to bdf87

The change may place pull-request builds on a different class of runner. Existing credential controls limit the apparent exposure, but the new runner’s isolation needs confirmation before its security impact can be settled.

Retained concerns

  • Low · security · inferred: CodeQL now executes fork-eligible pull-request builds on ubuntu-latest-max, whose runner isolation and shared-state policy are unverified. Whether this introduces access to more sensitive runner state depends on the external runner configuration.
Security review details

Security Blast Radius

  • inferred — Fork-controlled build code can run in the CodeQL job for this repository. Exposure beyond that job depends on the new runner’s persistence, network access, and sharing with other workloads; those properties are unverified. QA already uses the same label and has a conditional build step supplied with signing credentials.

Security Findings and Attack Paths

  • inferred — No unsafe runner or exploit path is established. The conditional path of concern is fork pull-request content executing Gradle code on a newly selected runner that retains sensitive state or has privileged access.

Trust Boundaries and Controls

  • observed — The workflow has no fork exclusion before checkout and build. It also avoids pull_request_target and persisted checkout credentials; the declared security-events write permission does not establish the token authority actually granted to fork runs.

Resilience and Maintainability Implications

  • inferred — Runner availability affects whether CodeQL analysis runs, and any cross-run cleanup guarantee must come from the runner configuration rather than the workflow’s build steps. Neither guarantee is established for the new label.

Hardening Proposals

  • proposed — Confirm the label’s runner ownership, fork-job eligibility, ephemerality or cleanup, network access, and effective fork-token policy before relying on it for CodeQL; otherwise keep fork builds on a demonstrably isolated runner.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description clearly explains that the workflow directory was synchronized and identifies the automation source. It does not include the repository template sections for screenshots, TODO items, ch… Add the required template sections: Screenshots, TODO, Checklist, and AI. Mark each checklist item as completed or not needed, and state whether tests or capability checks were required.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title accurately identifies an automatic synchronization with nextcloud/android-config. It is concise and related to the main change, although it does not specify that workflow files were synchron…
Full details: Description check

Explanation

The description clearly explains that the workflow directory was synchronized and identifies the automation source. It does not include the repository template sections for screenshots, TODO items, checklist status, or AI disclosure.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 569c0fad-2452-4d74-ae26-645bb39b393b

📥 Commits

Reviewing files that changed from the base of the PR and between a5ebeb0 and dd7e6a8.

📒 Files selected for processing (4)
  • .github/workflows/analysis.yml
  • .github/workflows/codeql.yml
  • .github/workflows/qa.yml
  • .github/workflows/scorecard.yml

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.

with:
distribution: "temurin"
java-version: 21
java-version: 25

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🔎 Supported by static analysis

🏁 Script executed:

set -eu
printf '%s\n' '--- revisions ---'
git rev-parse --verify dd7e6a8db3c793a15773529dd83659d846d1455a
git rev-parse --verify a5ebeb04c457b6b549a42213db873cddd6555c5e
printf '%s\n' '--- changed paths ---'
git diff --name-status a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a
printf '%s\n' '--- analysis workflow ---'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/analysis.yml | nl -ba | sed -n '45,78p'
printf '%s\n' '--- qa workflow ---'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/qa.yml | nl -ba | sed -n '22,52p'
printf '%s\n' '--- daemon properties ---'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:gradle/gradle-daemon-jvm.properties | nl -ba
printf '%s\n' '--- relevant diff ---'
git diff --unified=20 a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a -- .github/workflows/analysis.yml .github/workflows/qa.yml gradle/gradle-daemon-jvm.properties

Repository: nextcloud/talk-android

Length of output: 9704


🏁 Script executed:

set -eu
git rev-parse --verify dd7e6a8db3c793a15773529dd83659d846d1455a
git rev-parse --verify a5ebeb04c457b6b549a42213db873cddd6555c5e
git diff --name-status a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/analysis.yml | nl -ba | sed -n '45,78p'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/qa.yml | nl -ba | sed -n '22,52p'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:gradle/gradle-daemon-jvm.properties | nl -ba
git diff --unified=20 a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a -- .github/workflows/analysis.yml .github/workflows/qa.yml gradle/gradle-daemon-jvm.properties

Repository: nextcloud/talk-android

Length of output: 9570


🏁 Script executed:

printf '%s\n' '--- changed paths ---'
git diff --name-status a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a
printf '%s\n' '--- analysis workflow ---'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/analysis.yml | nl -ba | sed -n '45,78p'
printf '%s\n' '--- qa workflow ---'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/qa.yml | nl -ba | sed -n '22,52p'
printf '%s\n' '--- daemon properties ---'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:gradle/gradle-daemon-jvm.properties | nl -ba
printf '%s\n' '--- relevant diff ---'
git diff --unified=20 a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a -- .github/workflows/analysis.yml .github/workflows/qa.yml gradle/gradle-daemon-jvm.properties

Repository: nextcloud/talk-android

Length of output: 9604


🏁 Script executed:

git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/analysis.yml | sed -n '55,70p'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:.github/workflows/qa.yml | sed -n '30,45p'
git show dd7e6a8db3c793a15773529dd83659d846d1455a:gradle/gradle-daemon-jvm.properties
git diff --unified=5 a5ebeb04c457b6b549a42213db873cddd6555c5e dd7e6a8db3c793a15773529dd83659d846d1455a -- .github/workflows/analysis.yml .github/workflows/qa.yml gradle/gradle-daemon-jvm.properties

Repository: nextcloud/talk-android

Length of output: 4316


Align the Gradle daemon JVM with Java 25 when these jobs must test Gradle on Java 25.

Both workflows select Java 25, but gradle/gradle-daemon-jvm.properties pins the Gradle daemon to Java 21. Gradle gives daemon JVM criteria precedence over JAVA_HOME, so the daemon remains on Java 21. If Java 25 is intended only for the Gradle client, keep the current criterion.

Suggested fix
-toolchainVersion=21
+toolchainVersion=25
📍 Affects 2 files
  • .github/workflows/analysis.yml#L63-L63 (this comment)
  • .github/workflows/qa.yml#L38-L38

@nextcloud-android-bot
nextcloud-android-bot force-pushed the repo-sync/android-config/master branch from dd7e6a8 to cf7b59d Compare September 27, 2026 07:35
@AndyScherzinger
AndyScherzinger force-pushed the repo-sync/android-config/master branch from cf7b59d to ce86f94 Compare September 27, 2026 21:57
@nextcloud-android-bot
nextcloud-android-bot force-pushed the repo-sync/android-config/master branch 2 times, most recently from 5900fab to bdf8793 Compare September 28, 2026 11:42
@AndyScherzinger AndyScherzinger added this to the 25.1.0 milestone Sep 28, 2026
@AndyScherzinger
AndyScherzinger force-pushed the repo-sync/android-config/master branch from 6910570 to aba46b0 Compare September 28, 2026 12:38
@nextcloud-android-bot
nextcloud-android-bot force-pushed the repo-sync/android-config/master branch from aba46b0 to 9af98c5 Compare September 29, 2026 07:52
Signed-off-by: nextcloud-android-bot <android@nextcloud.com>
@nextcloud-android-bot
nextcloud-android-bot force-pushed the repo-sync/android-config/master branch from 9af98c5 to d12983d Compare September 30, 2026 07:58
@github-actions

Copy link
Copy Markdown
Contributor

Codacy

Lint

TypemasterPR
Warnings138138
Errors1818

SpotBugs

CategoryBaseNew
Bad practice77
Correctness1111
Dodgy code4545
Internationalization33
Malicious code vulnerability33
Performance88
Security1111
Total8888

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants