CI: Move update-dp job to build.yml workflow#229
Conversation
When formatting the comment containing the list of vulnerable packages for the PR, we accidentally overwrite the content of the "body" variable, which results in the HTML tags being lost, and the full table being always displayed (instead of hidden in a "<details>" block). Let's fix it. Fixes: da0cf47 ("Clean up SBOM") Signed-off-by: Quentin Monnet <qmo@qmon.net>
There was a problem hiding this comment.
Pull request overview
This PR refactors the dataplane bump workflow by moving the update-dp job from a standalone workflow file into the build.yml workflow. This eliminates the inefficient 45-minute sleep period and ensures the bump occurs immediately after the build job successfully completes.
Changes:
- Removed the standalone update-dp.yml workflow file entirely
- Added a new bump-dp job to build.yml that runs after the "run" job completes when pushing to main
- Fixed a formatting bug in the vulnerable packages comment generation (line 181)
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| .github/workflows/update-dp.yml | Complete removal of the standalone workflow that previously handled dataplane bumps with a 45-minute sleep |
| .github/workflows/build.yml | Added bump-dp job to run after successful build completion; fixed comment formatting bug on line 181 |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
2a3e1a7 to
3fc15df
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
| priority | nix_package | version_local | version_nixpkgs | version_upstream |
|---|---|---|---|---|
| 13 | glibc | 2.42-47 | 2.42 | 2.43 |
| 11 | binutils | 2.44 | 2.44 | 2.45.1 |
| 10 | pcre2 | 10.46 | 10.46 | 10.47 |
| 4 | openssl | 3.6.0 | 1.1.1w | 3.6.1 |
| 4 | openssl | 3.6.0 | 3.6.0 | 3.6.1 |
| 4 | kmod | 31 | 31 | 34.2 |
| 4 | numactl | 2.0.18 | 2.0.18 | 2.0.19 |
| 2 | dpdk | 25.07 | 25.07 | 25.11 |
|
| vuln_id | url | package | severity | version_local | version_nixpkgs | version_upstream | package_repology | sortcol | classify |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-22184 | https://nvd.nist.gov/vuln/detail/CVE-2026-22184 | zlib | 9.8 | 1.3.1 | 1.3.1 | 1.3.1 | zlib | 2026A0000022184 | fix_not_available |
| CVE-2025-8225 | https://nvd.nist.gov/vuln/detail/CVE-2025-8225 | binutils | 3.3 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000008225 | fix_update_to_version_upstream |
| CVE-2025-8224 | https://nvd.nist.gov/vuln/detail/CVE-2025-8224 | binutils | 3.3 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000008224 | fix_update_to_version_upstream |
| CVE-2025-6170 | https://nvd.nist.gov/vuln/detail/CVE-2025-6170 | libxml2 | 2.5 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2025A0000006170 | err_not_vulnerable_based_on_repology |
| CVE-2025-6021 | https://nvd.nist.gov/vuln/detail/CVE-2025-6021 | libxml2 | 7.5 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2025A0000006021 | err_not_vulnerable_based_on_repology |
| CVE-2025-3198 | https://nvd.nist.gov/vuln/detail/CVE-2025-3198 | binutils | 3.3 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000003198 | fix_update_to_version_upstream |
| CVE-2025-1153 | https://nvd.nist.gov/vuln/detail/CVE-2025-1153 | binutils | 3.1 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000001153 | fix_update_to_version_upstream |
| OSV-2024-698 | https://osv.dev/OSV-2024-698 | libxml2 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2024A0000000698 | err_not_vulnerable_based_on_repology | |
| CVE-2023-6992 | https://nvd.nist.gov/vuln/detail/CVE-2023-6992 | zlib | 4.0 | 1.3.1 | 1.3.1 | 1.3.1 | zlib | 2023A0000006992 | err_not_vulnerable_based_on_repology |
| CVE-2023-4039 | https://nvd.nist.gov/vuln/detail/CVE-2023-4039 | gcc | 4.8 | 15.2.0 | 15.2.0 | 15.2.0 | gcc | 2023A0000004039 | fix_not_available |
| OSV-2021-777 | https://osv.dev/OSV-2021-777 | libxml2 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2021A0000000777 | err_not_vulnerable_based_on_repology | |
| CVE-2016-2781 | https://nvd.nist.gov/vuln/detail/CVE-2016-2781 | coreutils | 6.5 | 9.9 | 9.9 | 9.9 | coreutils | 2016A0000002781 | fix_not_available |
When pushing to the main branch, we currently trigger a job that waits for 45 minutes - to give time to the build.yml to build and push the new container images - before trying to bump the dpdk-sys reference in the dataplane repository. Instead, it makes more sense to move this job to the build.yml workflow, so that it can start right after the "run" job has successfully completed. This avoids creating a job that sleeps for 45 minutes, and remove the risk that after these 45 minutes the new images are not ready anyway (if the "run" job took longer than that, which occasionally occurs, or if it failed). Signed-off-by: Quentin Monnet <qmo@qmon.net>
3fc15df to
8a06b15
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
| priority | nix_package | version_local | version_nixpkgs | version_upstream |
|---|---|---|---|---|
| 13 | glibc | 2.42-47 | 2.42 | 2.43 |
| 11 | binutils | 2.44 | 2.44 | 2.45.1 |
| 10 | pcre2 | 10.46 | 10.46 | 10.47 |
| 4 | kmod | 31 | 31 | 34.2 |
| 4 | openssl | 3.6.0 | 1.1.1w | 3.6.1 |
| 4 | openssl | 3.6.0 | 3.6.0 | 3.6.1 |
| 4 | numactl | 2.0.18 | 2.0.18 | 2.0.19 |
| 2 | dpdk | 25.07 | 25.07 | 25.11 |
|
| vuln_id | url | package | severity | version_local | version_nixpkgs | version_upstream | package_repology | sortcol | classify |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-22184 | https://nvd.nist.gov/vuln/detail/CVE-2026-22184 | zlib | 9.8 | 1.3.1 | 1.3.1 | 1.3.1 | zlib | 2026A0000022184 | fix_not_available |
| CVE-2025-8225 | https://nvd.nist.gov/vuln/detail/CVE-2025-8225 | binutils | 3.3 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000008225 | fix_update_to_version_upstream |
| CVE-2025-8224 | https://nvd.nist.gov/vuln/detail/CVE-2025-8224 | binutils | 3.3 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000008224 | fix_update_to_version_upstream |
| CVE-2025-6170 | https://nvd.nist.gov/vuln/detail/CVE-2025-6170 | libxml2 | 2.5 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2025A0000006170 | err_not_vulnerable_based_on_repology |
| CVE-2025-6021 | https://nvd.nist.gov/vuln/detail/CVE-2025-6021 | libxml2 | 7.5 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2025A0000006021 | err_not_vulnerable_based_on_repology |
| CVE-2025-3198 | https://nvd.nist.gov/vuln/detail/CVE-2025-3198 | binutils | 3.3 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000003198 | fix_update_to_version_upstream |
| CVE-2025-1153 | https://nvd.nist.gov/vuln/detail/CVE-2025-1153 | binutils | 3.1 | 2.44 | 2.44 | 2.45.1 | binutils | 2025A0000001153 | fix_update_to_version_upstream |
| OSV-2024-698 | https://osv.dev/OSV-2024-698 | libxml2 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2024A0000000698 | err_not_vulnerable_based_on_repology | |
| CVE-2023-6992 | https://nvd.nist.gov/vuln/detail/CVE-2023-6992 | zlib | 4.0 | 1.3.1 | 1.3.1 | 1.3.1 | zlib | 2023A0000006992 | err_not_vulnerable_based_on_repology |
| CVE-2023-4039 | https://nvd.nist.gov/vuln/detail/CVE-2023-4039 | gcc | 4.8 | 15.2.0 | 15.2.0 | 15.2.0 | gcc | 2023A0000004039 | fix_not_available |
| OSV-2021-777 | https://osv.dev/OSV-2021-777 | libxml2 | 2.15.1 | 2.15.1 | 2.15.1 | libxml2 | 2021A0000000777 | err_not_vulnerable_based_on_repology | |
| CVE-2016-2781 | https://nvd.nist.gov/vuln/detail/CVE-2016-2781 | coreutils | 6.5 | 9.9 | 9.9 | 9.9 | coreutils | 2016A0000002781 | fix_not_available |
|
Got no review yesterday, I'm merging this - it doesn't affect any of the code and I'll keep looking after the update workflow to make sure it works as expected. |
When pushing to the main branch, we currently trigger a job that waits for 45 minutes - to give time to the build.yml to build and push the new container images - before trying to bump the dpdk-sys reference in the dataplane repository.
Instead, it makes more sense to move this job to the build.yml workflow, so that it can start right after the "run" job has successfully completed. This avoids creating a job that sleeps for 45 minutes, and remove the risk that after these 45 minutes the new images are not ready anyway (if the "run" job took longer than that, which occasionally occurs, or if it failed).
Fixes: #169
Also fix the formatting of auto-generated comments in PRs for build.yml.