Repository navigation
fix(kyverno): guard CRD spec getters with optional chaining - #1107
Open
vikash7485 wants to merge 1 commit into
Open
vikash7485 wants to merge 1 commit into
vikash7485 wants to merge 1 commit into
Conversation
vikash7485
requested review from
ashu8912,
illume,
joaquimrocha,
skoeva,
sniok,
vyncent-t and
yolossn
as code owners
August 10, 2026 09:35
vikash7485
force-pushed
the
fix/kyverno-optional-chaining-spec-getters
branch
2 times, most recently
from
August 10, 2026 09:38
36ff112 to
3997e18
Compare
illume
requested changes
Sep 29, 2026
illume
left a comment
Contributor
There was a problem hiding this comment.
Thanks for working on this.
The commit messages could use some tidying up to match our contribution guidelines. We use Linux kernel style — the contributing guide has the details, and git log shows good examples.
Commits that need attention
fix(kyverno): guard CRD spec getters with optional chaining— Missingarea: descriptionprefix — e.g.frontend: HomeButton: Fix so it navigates to homeorbackend: config: Add enable-dynamic-clusters flag.
Commit guidelines
- Use atomic commits focused on a single change.
- Use the title format
<area>: <Description of changes>— description must start with a capital letter. - Keep the title under 72 characters (soft requirement).
- Explain the intention and why the change is needed.
- Make commit titles meaningful and describe what changed.
- Do not add code that a later commit rewrites; squash or reorder commits instead.
- Do not include
Fixes #NNin commit messages.
Good examples:
frontend: HomeButton: Fix so it navigates to homebackend: config: Add enable-dynamic-clusters flag
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new fixtures omit a type-required spec, causing typechecking failures until the resource interfaces reflect the supported payload shape.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds safe defaults for Kyverno resources whose spec is missing or incomplete.
Changes:
- Guards traditional and CEL policy getters with optional chaining.
- Adds regression coverage for missing specifications.
| File | Description |
|---|---|
kyverno/src/resources/kyvernoPolicy.ts |
Safeguards standard policy getters. |
kyverno/src/resources/celPolicies.ts |
Safeguards CEL policy getters. |
kyverno/src/resources/kyvernoPolicy.test.ts |
Tests missing-spec fallback behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Safely handle missing or partial spec definitions across KyvernoPolicy and CEL-based policy resource classes with optional spec interfaces and fallback getters. Signed-off-by: vikash7485 <vikkiraj073@gmail.com>
vikash7485
force-pushed
the
fix/kyverno-optional-chaining-spec-getters
branch
from
September 30, 2026 17:37
3997e18 to
779bfbb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Fixes potential runtime crashes (
TypeError: Cannot read properties of undefined (reading 'rules')) when rendering Kyverno policies (Policy,ClusterPolicy,ValidatingPolicy,MutatingPolicy,GeneratingPolicy,DeletingPolicy,ImageValidatingPolicy) whose Kubernetes resource payloads omit or partially initialize the.specobject field.Root Cause
KyvernoPolicyBaseinsrc/resources/kyvernoPolicy.tsand CEL policy wrappers (ValidatingPolicy,MutatingPolicy,GeneratingPolicy,DeletingPolicy,ImageValidatingPolicy) insrc/resources/celPolicies.tsdereferencedthis.specdirectly without optional chaining. When a resource's.specfield is undefined during streaming or mock loading, calling getters like.rules,.validationFailureAction,.background, or.validationCountthrew an unhandledTypeError.Changes Made
plugins/kyverno/src/resources/kyvernoPolicy.ts:rules,validationFailureAction, andbackgroundgetters to evaluatethis.spec?.....plugins/kyverno/src/resources/celPolicies.ts:validationActions,validationCount,isAdmissionEnabled,isBackgroundEnabled,mutationCount,generateCount,schedule,imagePatterns, andattestorCountgetters to evaluatethis.spec?.....plugins/kyverno/src/resources/kyvernoPolicy.test.ts:.specisundefined.How to Test
npm testinsideplugins/kyvernoto execute the new unit test suite insrc/resources/kyvernoPolicy.test.ts.{ kind: 'Policy', metadata: { name: 'test' } }evaluate.rules,.validationFailureAction, and.backgroundwithout throwing runtime errors.