)]}'
{
  "commit": "e3b8484730dace16b71d69c3164c39721e983318",
  "tree": "53165e0b5a2a4e1e187852fbaece0514a78a717b",
  "parents": [
    "2f77407ce5f49a1a38722f3c2437cdcab2561413"
  ],
  "author": {
    "name": "Luca Milanesio",
    "email": "luca.milanesio@gmail.com",
    "time": "Fri Oct 02 10:01:05 2026 +0100"
  },
  "committer": {
    "name": "Luca Milanesio",
    "email": "luca.milanesio@gmail.com",
    "time": "Fri Oct 02 07:29:31 2026 -0700"
  },
  "message": "Disable validation of Jenkinsfile changes\n\nThe validation of arbitrary Jenkinsfile changes allows for Remote Code\nExecution (RCE) on the Jenkins controller and agents. This may allow\nunauthorised write access to untrusted build artifacts (e.g.,\n/var/jenkins_home/jobs), disclosure of untrusted credentials (including\nGit read-only credentials for fetching code for builds, BuildBuddy RBE\nkeys for accessing the build cache).\n\nThe RCE is, however, inherently linked with the concept of CI/CD because\nthe whole point of build validation is to fetch _potentially untrusted_\ncode from a contributor and running it on a server system.\n\nAll the credentials potentially exposed are untrusted and have no power\nto submit or push any code to Gerrit. The sole purpose of the service\nusers running the build is to provide a `Verified` label, and they\ncannot approve any incoming change automatically.\n\nBug: Issue 568458159\nChange-Id: I2c1c6c16714d2297424ba15a4fa4ed021964d2e3\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "a7a1010e902bf1769f9e51bd716e78a9ef140d45",
      "old_mode": 33188,
      "old_path": "jenkins-internal/gerrit-ci-scripts.yaml",
      "new_id": "632d42fd3032ded2a5e7eaf7bea7bed85c09a9ea",
      "new_mode": 33188,
      "new_path": "jenkins-internal/gerrit-ci-scripts.yaml"
    },
    {
      "type": "modify",
      "old_id": "3a4f23bb2f037294e5b3650ce8f6a46a0443a2ce",
      "old_mode": 33188,
      "old_path": "jenkins/gerrit-bazel-plugin-template.yaml",
      "new_id": "798091551c5c529bd7eb725fe78a869e56d66ad4",
      "new_mode": 33188,
      "new_path": "jenkins/gerrit-bazel-plugin-template.yaml"
    },
    {
      "type": "modify",
      "old_id": "6d91e79cad7be53883e97bb3a18db27816350913",
      "old_mode": 33188,
      "old_path": "jenkins/gerrit-ci-scripts.yaml",
      "new_id": "4ef208ac6002afeb2e803d0c97502f85f1c407be",
      "new_mode": 33188,
      "new_path": "jenkins/gerrit-ci-scripts.yaml"
    },
    {
      "type": "modify",
      "old_id": "f425ce579874a5d9f484a711387a6c2ad21cfacf",
      "old_mode": 33188,
      "old_path": "jenkins/gerrit-verifier.yaml",
      "new_id": "b6a412d3f28c4616db488c6edfe7cf778a651d4a",
      "new_mode": 33188,
      "new_path": "jenkins/gerrit-verifier.yaml"
    }
  ]
}
