Repository navigation
Conversation
Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
Contributor
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 8bded97 in the Show a line coverage summary of the most impacted files.
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Makes the trusted Portable Podman 5.7 builder resolve its pinned build packages and transitive dependencies only from the reviewed signed Ubuntu snapshot. A newer GitHub runner package set can no longer override the snapshot with incompatible dependency versions.
Reason
Trusted E2E run 37498354030 failed before the Portable Hermes workload because the runner mixed current Ubuntu indexes and installed newer packages with the exact snapshot pins. The resulting git, AppArmor, GLib, and SQLite version skew made APT reject the build dependency set. This is canonical workflow infrastructure, not a #12244 candidate defect.
Related issues
Part of #11892
Prerequisite for #12244
Changes
Verification
npx vitest run --project e2e-support test/e2e/support/native-podman-setup-action.test.ts— 25 tests passed.npx vitest run --project e2e-support test/e2e/support/native-podman-setup-action.test.ts test/e2e/support/shared-e2e-workflow-boundary.test.ts test/e2e/support/e2e-host-dependency-workflow-boundary.test.ts— 288 tests passed.npm run test:changed— growth guardrails and 25 selected E2E-support tests passed.npm run checks:repository— all 18 repository checks passed.npm run validate:pr— committed-tree hooks, builds, publication validation, and TypeScript checks passed.Review notes
This changes a sensitive trusted workflow boundary. The failure and repair are limited to the pre-workload Portable Podman builder. After merge, #12244 still requires a fresh trusted
portable-hermes-finalizationrun from canonical main before it can become ready for review.Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com