Skip to content

feat(ISV-5783): Use new SBOM generation workflow#950

Merged
johnbieren merged 1 commit intokonflux-ci:developmentfrom
jedinym:ISV-5783
May 22, 2025
Merged

feat(ISV-5783): Use new SBOM generation workflow#950
johnbieren merged 1 commit intokonflux-ci:developmentfrom
jedinym:ISV-5783

Conversation

@jedinym
Copy link
Copy Markdown
Contributor

@jedinym jedinym commented May 12, 2025

With the refactoring of the SBOM generation process (konflux-ci/release-service-utils#418, konflux-ci/release-service-utils#415, konflux-ci/release-service-utils#399), we can simplify the rh-advisories pipeline.

The SBOM generation task are now only dependent on apply-mapping.

Changes

  • The populate-release-notes Task no longer generates data used to generate SBOMs.
  • The push-rpm-data-to-pyxis Task no longer exports a result with the SBOM directory.
  • The update-component-sbom Task is no longer dependent on populate-release-notes and push-rpm-data-to-pyxis.
  • The create-product-sbom Task is no longer dependent on populate-release-notes.

Relevant Jira

https://issues.redhat.com/browse/ISV-5783

@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented May 12, 2025

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 12, 2025

/ok-to-test

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 12, 2025

/retest

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 14, 2025

/retest

4 similar comments
@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 14, 2025

/retest

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 14, 2025

/retest

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 14, 2025

/retest

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 15, 2025

/retest

@jedinym jedinym marked this pull request as ready for review May 15, 2025 09:16
@jedinym jedinym requested a review from a team as a code owner May 15, 2025 09:16
@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 15, 2025

@konflux-ci/release-service-maintainers The E2E tests are not cooperating, could you please take a look in the meantime?

@mmalina
Copy link
Copy Markdown
Contributor

mmalina commented May 15, 2025

@konflux-ci/release-service-maintainers The E2E tests are not cooperating, could you please take a look in the meantime?

I will review later today. Meanwhile, Scott merged another PR that changed the pipeline, so you will need to resolve conflicts (likely just the version and readme).

Copy link
Copy Markdown
Contributor

@mmalina mmalina left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few small comments, but overall it looks good.

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 20, 2025

/retest

2 similar comments
@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 20, 2025

/retest

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 20, 2025

/retest

@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 20, 2025

Blocked by konflux-ci/release-service-utils#436

@jedinym jedinym force-pushed the ISV-5783 branch 3 times, most recently from 4f0337d to 6d5c777 Compare May 21, 2025 14:09
@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 21, 2025

@konflux-ci/release-service-maintainers Once the release-service-utils release is resolved, this PR is ready to merge. It's important for us that we get this into staging today.

@johnbieren
Copy link
Copy Markdown
Collaborator

@konflux-ci/release-service-maintainers Once the release-service-utils release is resolved, this PR is ready to merge. It's important for us that we get this into staging today.

You don't even have passing unit tests

@jedinym jedinym force-pushed the ISV-5783 branch 2 times, most recently from 6ff7cde to 601f1cb Compare May 22, 2025 07:52
@jedinym
Copy link
Copy Markdown
Contributor Author

jedinym commented May 22, 2025

@konflux-ci/release-service-maintainers could you please try rerunning the GH actions?

@mmalina
Copy link
Copy Markdown
Contributor

mmalina commented May 22, 2025

@konflux-ci/release-service-maintainers could you please try rerunning the GH actions?

Triggered now. I noticed these issues with github assigning runners elsewhere too.

@johnbieren
Copy link
Copy Markdown
Collaborator

Noting that this has passing e2e right now so once the README thing is fixed and it is rebased, we should be able to merge without e2e

@johnbieren
Copy link
Copy Markdown
Collaborator

Can you squash the commits when you rebase?

mmalina
mmalina previously approved these changes May 22, 2025
Copy link
Copy Markdown
Contributor

@mmalina mmalina left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, once Johnny's remaining thread is addressed.

The SBOM generation logic is now dependent on fewer tasks.

Signed-off-by: Martin Jediny <jedinym@proton.me>
@openshift-ci openshift-ci bot added the lgtm label May 22, 2025
@johnbieren
Copy link
Copy Markdown
Collaborator

Merging without waiting for e2e, as it had passing e2e and only a text file changed

@johnbieren johnbieren merged commit 10b8e10 into konflux-ci:development May 22, 2025
8 of 9 checks passed
happybhati pushed a commit that referenced this pull request Sep 11, 2025
The SBOM generation logic is now dependent on fewer tasks.

Signed-off-by: Martin Jediny <jedinym@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants