ci: use blossom-action main-v2 for the vulnerability scan - #1078
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review. 📝 WalkthroughWalkthroughThe ChangesVulnerability scan workflow
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The workflow switches to 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
The Pulse scanner in blossom-action@main runs with its working directory set to the repository checkout, so pyenv picks up our .python-version (3.14), which the image does not have, and the scan exits before it starts. main-v2 no longer sets the working directory to the checkout and passes it to the scanner as a path instead. Refs: HPCINFRA-4862 Signed-off-by: Or Balayla <obalayla@nvidia.com>
708a483 to
362ad6e
Compare
Summary
The Blossom vulnerability scan fails on every PR before it starts:
blossom-action@mainruns the Pulse scanner container with-w /src, so pyenv picks up our.python-version. Blossom pointed us atmain-v2, which drops-w /srcand passes/srcto the scanner as the scan path. The container then starts in the image's own working directory and no longer reads our.python-version.This PR switches
blossom-ci.ymltoNVIDIA/blossom-action@main-v2. Nothing else changes.Refs: HPCINFRA-4862
Test Plan
blossom-actionbinaries onmainandmain-v2. OnlydoVulnerabilityScandiffers, and the difference is the-w /srcremoval described above.pre-commit run --files .github/workflows/blossom-ci.ymlpasses.blossom-ci.ymlruns onissue_comment, so GitHub always uses the copy onmain. After merge: comment/buildon a PR that still has.python-versionset to 3.14 and check thatVulnerability scanpasses andStart ci jobruns.Additional Notes
Blossom checks the workflow against its templates. Blossom asked for this ref, so the check should accept it. If the first run after merge fails with "does not match any supported template version", revert this PR.