Skip to content

Webhook crashes when workflow_job is null #5512

Description

@randall-shults

Overview

The webhook Lambda crashes when GitHub sends a workflow_job event whose workflow_job field is null or missing. The delivery is otherwise valid and signature-verified, but readWorkflowJobEvent dereferences event.workflow_job.name before validating the field.

Version

v7.11.0 and current main (faf57cd1).

Reproduction

Add this synthetic case to lambdas/functions/webhook/src/webhook/index.test.ts:

it('should accept without dispatching when workflow_job is null', async () => {
  const event = JSON.stringify({ ...workFlowJobEvent, workflow_job: null });

  await expect(
    publishForRunners(
      { 'X-Hub-Signature-256': await webhooks.sign(event), 'X-GitHub-Event': 'workflow_job' },
      event,
      config,
    ),
  ).resolves.toMatchObject({ statusCode: 202 });
  expect(dispatch).not.toHaveBeenCalled();
});

The test fails with:

TypeError: Cannot read properties of null (reading 'name')
  at readWorkflowJobEvent src/webhook/index.ts:149:32
  at Module.publishForRunners src/webhook/index.ts:24:32

Expected behavior

After signature verification, a workflow_job delivery with a null or missing workflow_job should be logged at warn level and accepted without queue dispatch or EventBridge publication. This prevents an unusable delivery from failing the Lambda invocation while ensuring it cannot create runner demand.

I have a small regression-tested fix ready to submit.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions