Skip to content

CI: Move update-dp job to build.yml workflow#229

Merged
qmonnet merged 2 commits intomainfrom
pr/qmonnet/ci-improv
Jan 29, 2026
Merged

CI: Move update-dp job to build.yml workflow#229
qmonnet merged 2 commits intomainfrom
pr/qmonnet/ci-improv

Conversation

@qmonnet
Copy link
Member

@qmonnet qmonnet commented Jan 28, 2026

When pushing to the main branch, we currently trigger a job that waits for 45 minutes - to give time to the build.yml to build and push the new container images - before trying to bump the dpdk-sys reference in the dataplane repository.

Instead, it makes more sense to move this job to the build.yml workflow, so that it can start right after the "run" job has successfully completed. This avoids creating a job that sleeps for 45 minutes, and remove the risk that after these 45 minutes the new images are not ready anyway (if the "run" job took longer than that, which occasionally occurs, or if it failed).

Fixes: #169

Also fix the formatting of auto-generated comments in PRs for build.yml.

When formatting the comment containing the list of vulnerable packages
for the PR, we accidentally overwrite the content of the "body"
variable, which results in the HTML tags being lost, and the full table
being always displayed (instead of hidden in a "<details>" block). Let's
fix it.

Fixes: da0cf47 ("Clean up SBOM")
Signed-off-by: Quentin Monnet <qmo@qmon.net>
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR refactors the dataplane bump workflow by moving the update-dp job from a standalone workflow file into the build.yml workflow. This eliminates the inefficient 45-minute sleep period and ensures the bump occurs immediately after the build job successfully completes.

Changes:

  • Removed the standalone update-dp.yml workflow file entirely
  • Added a new bump-dp job to build.yml that runs after the "run" job completes when pushing to main
  • Fixed a formatting bug in the vulnerable packages comment generation (line 181)

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
.github/workflows/update-dp.yml Complete removal of the standalone workflow that previously handled dataplane bumps with a 45-minute sleep
.github/workflows/build.yml Added bump-dp job to run after successful build completion; fixed comment formatting bug on line 181

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions
Copy link
Contributor

Outdated packages (gnu64):

priority nix_package version_local version_nixpkgs version_upstream
13 glibc 2.42-47 2.42 2.43
11 binutils 2.44 2.44 2.45.1
10 pcre2 10.46 10.46 10.47
4 openssl 3.6.0 1.1.1w 3.6.1
4 openssl 3.6.0 3.6.0 3.6.1
4 kmod 31 31 34.2
4 numactl 2.0.18 2.0.18 2.0.19
2 dpdk 25.07 25.07 25.11

@github-actions
Copy link
Contributor

Vulnerable packages (gnu64):

vuln_id url package severity version_local version_nixpkgs version_upstream package_repology sortcol classify
CVE-2026-22184 https://nvd.nist.gov/vuln/detail/CVE-2026-22184 zlib 9.8 1.3.1 1.3.1 1.3.1 zlib 2026A0000022184 fix_not_available
CVE-2025-8225 https://nvd.nist.gov/vuln/detail/CVE-2025-8225 binutils 3.3 2.44 2.44 2.45.1 binutils 2025A0000008225 fix_update_to_version_upstream
CVE-2025-8224 https://nvd.nist.gov/vuln/detail/CVE-2025-8224 binutils 3.3 2.44 2.44 2.45.1 binutils 2025A0000008224 fix_update_to_version_upstream
CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 libxml2 2.5 2.15.1 2.15.1 2.15.1 libxml2 2025A0000006170 err_not_vulnerable_based_on_repology
CVE-2025-6021 https://nvd.nist.gov/vuln/detail/CVE-2025-6021 libxml2 7.5 2.15.1 2.15.1 2.15.1 libxml2 2025A0000006021 err_not_vulnerable_based_on_repology
CVE-2025-3198 https://nvd.nist.gov/vuln/detail/CVE-2025-3198 binutils 3.3 2.44 2.44 2.45.1 binutils 2025A0000003198 fix_update_to_version_upstream
CVE-2025-1153 https://nvd.nist.gov/vuln/detail/CVE-2025-1153 binutils 3.1 2.44 2.44 2.45.1 binutils 2025A0000001153 fix_update_to_version_upstream
OSV-2024-698 https://osv.dev/OSV-2024-698 libxml2 2.15.1 2.15.1 2.15.1 libxml2 2024A0000000698 err_not_vulnerable_based_on_repology
CVE-2023-6992 https://nvd.nist.gov/vuln/detail/CVE-2023-6992 zlib 4.0 1.3.1 1.3.1 1.3.1 zlib 2023A0000006992 err_not_vulnerable_based_on_repology
CVE-2023-4039 https://nvd.nist.gov/vuln/detail/CVE-2023-4039 gcc 4.8 15.2.0 15.2.0 15.2.0 gcc 2023A0000004039 fix_not_available
OSV-2021-777 https://osv.dev/OSV-2021-777 libxml2 2.15.1 2.15.1 2.15.1 libxml2 2021A0000000777 err_not_vulnerable_based_on_repology
CVE-2016-2781 https://nvd.nist.gov/vuln/detail/CVE-2016-2781 coreutils 6.5 9.9 9.9 9.9 coreutils 2016A0000002781 fix_not_available

When pushing to the main branch, we currently trigger a job that waits
for 45 minutes - to give time to the build.yml to build and push the new
container images - before trying to bump the dpdk-sys reference in the
dataplane repository.

Instead, it makes more sense to move this job to the build.yml workflow,
so that it can start right after the "run" job has successfully
completed. This avoids creating a job that sleeps for 45 minutes, and
remove the risk that after these 45 minutes the new images are not ready
anyway (if the "run" job took longer than that, which occasionally
occurs, or if it failed).

Signed-off-by: Quentin Monnet <qmo@qmon.net>
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions
Copy link
Contributor

Outdated packages (gnu64):

priority nix_package version_local version_nixpkgs version_upstream
13 glibc 2.42-47 2.42 2.43
11 binutils 2.44 2.44 2.45.1
10 pcre2 10.46 10.46 10.47
4 kmod 31 31 34.2
4 openssl 3.6.0 1.1.1w 3.6.1
4 openssl 3.6.0 3.6.0 3.6.1
4 numactl 2.0.18 2.0.18 2.0.19
2 dpdk 25.07 25.07 25.11

@github-actions
Copy link
Contributor

Vulnerable packages (gnu64):

vuln_id url package severity version_local version_nixpkgs version_upstream package_repology sortcol classify
CVE-2026-22184 https://nvd.nist.gov/vuln/detail/CVE-2026-22184 zlib 9.8 1.3.1 1.3.1 1.3.1 zlib 2026A0000022184 fix_not_available
CVE-2025-8225 https://nvd.nist.gov/vuln/detail/CVE-2025-8225 binutils 3.3 2.44 2.44 2.45.1 binutils 2025A0000008225 fix_update_to_version_upstream
CVE-2025-8224 https://nvd.nist.gov/vuln/detail/CVE-2025-8224 binutils 3.3 2.44 2.44 2.45.1 binutils 2025A0000008224 fix_update_to_version_upstream
CVE-2025-6170 https://nvd.nist.gov/vuln/detail/CVE-2025-6170 libxml2 2.5 2.15.1 2.15.1 2.15.1 libxml2 2025A0000006170 err_not_vulnerable_based_on_repology
CVE-2025-6021 https://nvd.nist.gov/vuln/detail/CVE-2025-6021 libxml2 7.5 2.15.1 2.15.1 2.15.1 libxml2 2025A0000006021 err_not_vulnerable_based_on_repology
CVE-2025-3198 https://nvd.nist.gov/vuln/detail/CVE-2025-3198 binutils 3.3 2.44 2.44 2.45.1 binutils 2025A0000003198 fix_update_to_version_upstream
CVE-2025-1153 https://nvd.nist.gov/vuln/detail/CVE-2025-1153 binutils 3.1 2.44 2.44 2.45.1 binutils 2025A0000001153 fix_update_to_version_upstream
OSV-2024-698 https://osv.dev/OSV-2024-698 libxml2 2.15.1 2.15.1 2.15.1 libxml2 2024A0000000698 err_not_vulnerable_based_on_repology
CVE-2023-6992 https://nvd.nist.gov/vuln/detail/CVE-2023-6992 zlib 4.0 1.3.1 1.3.1 1.3.1 zlib 2023A0000006992 err_not_vulnerable_based_on_repology
CVE-2023-4039 https://nvd.nist.gov/vuln/detail/CVE-2023-4039 gcc 4.8 15.2.0 15.2.0 15.2.0 gcc 2023A0000004039 fix_not_available
OSV-2021-777 https://osv.dev/OSV-2021-777 libxml2 2.15.1 2.15.1 2.15.1 libxml2 2021A0000000777 err_not_vulnerable_based_on_repology
CVE-2016-2781 https://nvd.nist.gov/vuln/detail/CVE-2016-2781 coreutils 6.5 9.9 9.9 9.9 coreutils 2016A0000002781 fix_not_available

@qmonnet
Copy link
Member Author

qmonnet commented Jan 29, 2026

Got no review yesterday, I'm merging this - it doesn't affect any of the code and I'll keep looking after the update workflow to make sure it works as expected.

@qmonnet qmonnet merged commit b654138 into main Jan 29, 2026
16 checks passed
@qmonnet qmonnet deleted the pr/qmonnet/ci-improv branch January 29, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Improve dataplane bump workflow

1 participant