Overview
The webhook Lambda crashes when GitHub sends a workflow_job event whose workflow_job field is null or missing. The delivery is otherwise valid and signature-verified, but readWorkflowJobEvent dereferences event.workflow_job.name before validating the field.
Version
v7.11.0 and current main (faf57cd1).
Reproduction
Add this synthetic case to lambdas/functions/webhook/src/webhook/index.test.ts:
it('should accept without dispatching when workflow_job is null', async () => {
const event = JSON.stringify({ ...workFlowJobEvent, workflow_job: null });
await expect(
publishForRunners(
{ 'X-Hub-Signature-256': await webhooks.sign(event), 'X-GitHub-Event': 'workflow_job' },
event,
config,
),
).resolves.toMatchObject({ statusCode: 202 });
expect(dispatch).not.toHaveBeenCalled();
});
The test fails with:
TypeError: Cannot read properties of null (reading 'name')
at readWorkflowJobEvent src/webhook/index.ts:149:32
at Module.publishForRunners src/webhook/index.ts:24:32
Expected behavior
After signature verification, a workflow_job delivery with a null or missing workflow_job should be logged at warn level and accepted without queue dispatch or EventBridge publication. This prevents an unusable delivery from failing the Lambda invocation while ensuring it cannot create runner demand.
I have a small regression-tested fix ready to submit.
Overview
The webhook Lambda crashes when GitHub sends a
workflow_jobevent whoseworkflow_jobfield isnullor missing. The delivery is otherwise valid and signature-verified, butreadWorkflowJobEventdereferencesevent.workflow_job.namebefore validating the field.Version
v7.11.0 and current
main(faf57cd1).Reproduction
Add this synthetic case to
lambdas/functions/webhook/src/webhook/index.test.ts:The test fails with:
Expected behavior
After signature verification, a
workflow_jobdelivery with a null or missingworkflow_jobshould be logged at warn level and accepted without queue dispatch or EventBridge publication. This prevents an unusable delivery from failing the Lambda invocation while ensuring it cannot create runner demand.I have a small regression-tested fix ready to submit.