fix(ci): defer release aliases until security gates pass - #1763
Conversation
|
🌿 Preview your docs: https://nvidia-preview-fix-defer-release-alias-promotion.docs.buildwithfern.com/aicr |
Coverage Report ✅
Coverage BadgeCoverage unchanged by this PR. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: 📒 Files selected for processing (17)
📝 WalkthroughWalkthroughThe release pipeline now uses run-unique candidate tags and authoritative digest maps for scanning, attestation, promotion, and publication. Composite actions validate inputs before execution, SBOM generation covers both Linux platforms, and release scripts enforce image, release, asset, alias, and Homebrew integrity. Workflows, documentation, and comprehensive Go tests cover rerun safety and fail-closed promotion behavior. Estimated code review effort: 5 (Critical) | ~120 minutes Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
99bef9a to
5e380ca
Compare
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/actions/README.md:
- Around line 166-174: Add blank lines around the sbom-and-attest section
heading and the fenced YAML example in the README, ensuring the heading and code
fence are each separated from surrounding content to satisfy Markdown formatting
rules MD022 and MD031.
In @.github/actions/sbom-and-attest/action.yml:
- Around line 64-86: Update both Generate amd64 SBOM and Generate arm64 SBOM
configurations to set upload-release-assets explicitly to the intended boolean
value true instead of auto. Leave the remaining sbom-action inputs unchanged.
In @.github/workflows/on-tag.yaml:
- Around line 157-205: Move the security-sensitive Homebrew artifact naming,
validation, filesystem staging, and upload logic from the workflow steps “Name
Homebrew artifact,” “Stage Homebrew formula,” and “Upload Homebrew formula” into
a reusable Layer-2 composite. Apply the same extraction to the related manifest,
SSH setup, and Git mutation blocks, leaving Layer 3 responsible only for
orchestration; add an inline rationale comment wherever narrowly scoped logic
intentionally remains inline.
In `@RELEASING.md`:
- Around line 187-189: Update the promoted public tags statement in RELEASING.md
to include prerelease version aliases such as vX.Y.Z-rc… alongside latest and
stable vX.Y.Z, matching the release workflow behavior described earlier. Keep
the existing explanation of retained candidate tags unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Enterprise
Run ID: f2c7165c-258c-4351-9d19-f2050f2bfd55
📒 Files selected for processing (17)
.github/actions/README.md.github/actions/attest-image-from-tag/action.yml.github/actions/go-build-release/action.yml.github/actions/release-input-validation.sh.github/actions/sbom-and-attest/action.yml.github/scripts/publish-homebrew.sh.github/scripts/release-images.sh.github/workflows/attest-images.yaml.github/workflows/build-attested.yaml.github/workflows/on-tag.yaml.github/workflows/packaging.yaml.goreleaser.yamlRELEASING.mddocs/contributor/validator.mdtests/releasepolicy/doc.gotests/releasepolicy/release_scripts_test.gotests/releasepolicy/release_workflow_test.go
Signed-off-by: Mark Chmarny <mark@chmarny.com>
5e380ca to
92b6977
Compare
ArangoGutierrez
left a comment
There was a problem hiding this comment.
No issues found — checked for bugs and CLAUDE.md compliance.
Signed-off-by: Mark Chmarny <mark@chmarny.com>
Summary
Build all seven release images under a run-unique candidate tag, bind downstream security gates to one authoritative digest map, and promote public version/
latestaliases only after those gates pass. Keep GitHub releases in draft through promotion and publish Homebrew only after the validated release is public.Motivation / Context
The release graph previously exposed stable image aliases and the Homebrew formula before image vulnerability and provenance checks completed. This change makes public distribution the final, fail-closed phase and adds deterministic recovery for partial runs.
Fixes: N/A
Related: N/A
Type of Change
Component(s) Affected
cmd/aicr,pkg/cli)cmd/aicrd,pkg/server)pkg/recipe)pkg/bundler,pkg/component/*)pkg/collector,pkg/snapshotter)pkg/validator)pkg/errors,pkg/k8s)docs/,examples/)Implementation Notes
candidate-<run-id>-<attempt>first.linux/amd64andlinux/arm64for every image.lateststate before mutation.latestalias; prereleases remain version-only.latestbackward.Testing
All blocking checks passed. Project coverage is 78.8% against the 75% floor; the new Go package contains policy tests only, with no production statements or exported APIs. GoReleaser 2.17 validates the configuration but its standalone
checkcommand retains the existing exit-2 warning for the deprecatedbrewsproperty; the tokenless snapshot build succeeds and produces the expected archives, SBOMs, checksum, and Homebrew formula.Risk Assessment
Rollout notes: Applies to the next tag release without migration. Revert only before a release starts. If alias promotion is partially complete, fix the candidate path and rerun the same tag so the idempotent checks converge; do not manually repoint
latestor Homebrew.Checklist
make testwith-race)make lint)git commit -S) — GPG signing info