Skip to content

Guardrails

jenkins ​

2 guardrails, all at version v1.

GuardrailDefault severityWhat it checks
jenkins/job-timeout-setinfoEvery declarative pipeline declares how long it may run, either on the pipeline itself or on every stage, so a hung build is stopped instead of holding an executor.
jenkins/shared-library-pinnederrorEvery @Library annotation and library step names a tag or a commit SHA instead of a branch, so the library code a build runs can't change underneath it.

Shared inputs ​

Every jenkins guardrail declares these inputs. Individual guardrails can add their own.

InputDescriptionDefault
jenkinsfilesComma separated globs naming the Jenkinsfiles to read.Jenkinsfile,Jenkinsfile.*,*.Jenkinsfile

Shared collectors ​

Every jenkins guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.

CollectorGathers
jenkinsThe Jenkinsfiles the repository carries, read in Jenkins's own vocabulary: whether each is a declarative pipeline or a scripted one, the agent it asks for, the stages in the order they are declared with the steps inside them, the timeouts its options blocks declare, the shared libraries it loads and how tightly each is pinned, and the credential ids it reaches for. A Jenkinsfile is Groovy rather than a declaration, so it is read by pattern and scanned says so. Names and ids only, never a credential, an environment value or a parameter value.

You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.

Buildnote Limited
Registered in England and Wales, Reg: 16140412