Woodpecker CI 3.19 Adds Server-Enforced Agent Labels

Woodpecker CI 3.19 fixes a security issue involving matrix variables, adds server-enforced agent labels, and improves pipeline reliability.

Woodpecker CI, a lightweight, self-hosted CI/CD platform that works with popular Git services such as GitHub, GitLab, Gitea, and Forgejo, has released version 3.19.

The most important change addresses a security vulnerability that could allow matrix environment variables to be injected into the default repository cloning step. Developers have also improved secret sanitization during pipeline execution via the CLI, reducing the risk of sensitive information appearing in logs.

On the feature side, Woodpecker now supports server-enforced agent labels, giving administrators greater control over how build agents are identified and assigned work. Two new runtime environment variables, CI_AGENT_ID and CI_AGENT_LABELS, also make agent information available during pipeline execution.

Another addition is support for custom shell paths in the local backend, offering more flexibility when running pipelines directly on a host. The release also introduces default user namespace support with a configurable non-root override.

Pipeline management receives several improvements as well. Workflow and step dependencies are now stored in the database and exposed through the API, while agent listing gains pagination options.

Regarding bug fixes, Woodpecker CI 3.19 resolves an issue that caused step logs to disappear when a pipeline finished with skipped workflows. It also fixes race conditions during concurrent pipeline configuration storage, allows pipelines to restart after errors occurring before their configuration was saved, and prevents crashes when displaying workflows without steps.

Git hosting integrations receive attention, too. Bitbucket Cloud no longer encounters an infinite loop when paginating hooks, GitLab commit status handling has been corrected, and OAuth token refresh now reloads user information from storage beforehand.

For Kubernetes users, the update fixes workspace volume mismatches during CLI execution and ensures the informer cache is synchronized before checking pod deletion. The local backend also receives a fix for an agent crash when a workflow is canceled before its first step begins.

Other changes include disabling Windows cmd.exe AutoRun commands during local pipeline execution, improving agent shutdown handling, updating the project to Go 1.27, and refreshing numerous dependencies.

For more information, including the complete list of changes, see the release notes.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

Leave a Reply

Your email address will not be published. Required fields are marked *