Skip to content

ci: use blossom-action main-v2 for the vulnerability scan - #1078

Merged
orbalayla-nvidia merged 1 commit into
NVIDIA:mainfrom
orbalayla-nvidia:ci/blossom-action-main-v2
Oct 4, 2026
Merged

orbalayla-nvidia merged 1 commit into
NVIDIA:mainfrom
orbalayla-nvidia:ci/blossom-action-main-v2

Conversation

@orbalayla-nvidia

@orbalayla-nvidia orbalayla-nvidia commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The Blossom vulnerability scan fails on every PR before it starts:

pyenv: version `3.14' is not installed (set by /src/.python-version)

blossom-action@main runs the Pulse scanner container with -w /src, so pyenv picks up our .python-version. Blossom pointed us at main-v2, which drops -w /src and passes /src to the scanner as the scan path. The container then starts in the image's own working directory and no longer reads our .python-version.

This PR switches blossom-ci.yml to NVIDIA/blossom-action@main-v2. Nothing else changes.

Refs: HPCINFRA-4862

Test Plan

  • Compared the blossom-action binaries on main and main-v2. Only doVulnerabilityScan differs, and the difference is the -w /src removal described above.
  • pre-commit run --files .github/workflows/blossom-ci.yml passes.
  • This can't be verified on the PR itself. blossom-ci.yml runs on issue_comment, so GitHub always uses the copy on main. After merge: comment /build on a PR that still has .python-version set to 3.14 and check that Vulnerability scan passes and Start ci job runs.

Additional Notes

Blossom checks the workflow against its templates. Blossom asked for this ref, so the check should accept it. If the first run after merge fails with "does not match any supported template version", revert this PR.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/cloudai/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Enterprise
  • Run ID: 81e3c1ce-6d12-4c64-b778-1900b5858ea0
📥 Commits

Reviewing files that changed from the base of the PR and between 90bfa43 and 708a483.

📒 Files selected for processing (1)
  • .github/workflows/blossom-ci.yml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The Vulnerability-scan job in the Blossom CI workflow now references NVIDIA/blossom-action@main-v2 instead of NVIDIA/blossom-action@main.

Changes

Vulnerability scan workflow

Layer / File(s) Summary
Update Blossom action reference
.github/workflows/blossom-ci.yml
The Vulnerability-scan job now uses NVIDIA/blossom-action@main-v2.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix

Suggested reviewers: podkidyshev

Merge Risk: ⚪ Minimal · up to 708a4

The workflow switches to main-v2; the pinning concern was not a repository requirement, and the mutable-reference risk was already present. No concrete new merge-blocking issue is established.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the switch to NVIDIA/blossom-action@main-v2 for the vulnerability scan.
Description check ✅ Passed The description explains the scan failure, the action version change, and the planned verification. It is directly related to the changeset.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@orbalayla-nvidia
orbalayla-nvidia marked this pull request as ready for review October 4, 2026 04:57
@orbalayla-nvidia
orbalayla-nvidia requested a review from a team as a code owner October 4, 2026 04:57
The Pulse scanner in blossom-action@main runs with its working directory
set to the repository checkout, so pyenv picks up our .python-version
(3.14), which the image does not have, and the scan exits before it
starts. main-v2 no longer sets the working directory to the checkout and
passes it to the scanner as a path instead.

Refs: HPCINFRA-4862

Signed-off-by: Or Balayla <obalayla@nvidia.com>
@orbalayla-nvidia
orbalayla-nvidia force-pushed the ci/blossom-action-main-v2 branch from 708a483 to 362ad6e Compare October 4, 2026 06:38
@orbalayla-nvidia
orbalayla-nvidia merged commit c297601 into NVIDIA:main Oct 4, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants