Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .fullsend/customized/harness/retro.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
# SPDX-License-Identifier: Apache-2.0

# Derived retro harness: retain upstream analysis and append the Conforma gate.
base: https://raw.githubusercontent.com/fullsend-ai/agents/69ade99f1b61bea99aee98e604384e26ff7b45e0/harness/retro.yaml#sha256=6d858c90cc6f1c7526d2b36b8cd47df079d1332ac7184bb70dfb1587e9cb04d8
base: https://raw.githubusercontent.com/fullsend-ai/agents/ce2eedd097dcccf17e29f4a7cd337ec4d95d7194/harness/retro.yaml#sha256=510c52c1f662c876e81f13e5208302abaad4dd8b8d3705fdef21b908fa63d551

skills:
- customized/skills/retro-filing-policy
2 changes: 1 addition & 1 deletion .fullsend/customized/harness/review.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@
#
# SPDX-License-Identifier: Apache-2.0

base: https://raw.githubusercontent.com/fullsend-ai/agents/440d3e3c1a4a770309e37c2fd2826dfc88297d99/harness/review.yaml#sha256=c259d94e7c50e5e01cb0fa38df2b70765f8e35beb7ad8bf006c9193a05589917
base: https://raw.githubusercontent.com/fullsend-ai/agents/ce2eedd097dcccf17e29f4a7cd337ec4d95d7194/harness/review.yaml#sha256=3e9302d8143fcfd93df8e4542162776e98893c8ef367450679e2ffa89e5b0c53

# Fullsend's bool merge treats an omitted readonly_repo as false, so carry
# forward the upstream read-only guarantee explicitly.
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/fullsend.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ jobs:
issues: write
packages: read
pull-requests: write
uses: fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml@311c1ef517dcf51fba3167c701f188e856beaa7d
uses: fullsend-ai/fullsend/.github/workflows/reusable-dispatch.yml@ea66a0a1e5ecb0a08780042a6b283d104fcd02e3
with:
event_action: ${{ github.event.action }}
install_mode: per-repo
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/prioritize.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ concurrency:

jobs:
prioritize:
uses: fullsend-ai/fullsend/.github/workflows/reusable-prioritize.yml@311c1ef517dcf51fba3167c701f188e856beaa7d
uses: fullsend-ai/fullsend/.github/workflows/reusable-prioritize.yml@ea66a0a1e5ecb0a08780042a6b283d104fcd02e3
with:
event_type: ${{ inputs.event_type }}
source_repo: ${{ inputs.source_repo }}
Expand Down
62 changes: 62 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,68 @@ Read these before modifying the corresponding areas:
- [internal/validate/vsa/DESIGN.md](internal/validate/vsa/DESIGN.md) — VSA: storage backends, DSSE signing rationale, expiration model
- [acceptance/README.md](acceptance/README.md) — acceptance test framework, Testcontainers, WireMock, snapshot testing

## UBI Base Image Updates

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] intent-coherence

The PR body acknowledges that PR #3504 also adds a 'UBI Base Image Updates' section to AGENTS.md covering release-branch behavior. If both PRs land without pre-merge reconciliation, AGENTS.md will contain two sections with the same H2 heading. The PR author explicitly flags this and defers reconciliation.

Suggested fix: Coordinate with the author of PR #3504 to ensure whichever PR lands second is rebased and the sections merged. Git will surface a conflict naturally if both target the same region, so the risk is bounded.

Comment thread
jsmid1 marked this conversation as resolved.

The project pins the `ubi-minimal` base image digest in three Dockerfiles:

- `Dockerfile` (production)
- `Dockerfile.dist` (distribution)
- `acceptance/kubernetes/kind/acceptance.Dockerfile` (acceptance tests)

The script `hack/ubi-base-image-bump.sh` updates all three files to the same
digest and then invokes `hack/update-rpm-lock.sh` to regenerate `rpms.lock.yaml`.
Renovate raises the same bump automatically; the script exists for manual runs
between Renovate PRs. All three Dockerfiles must pin the same digest, and the
lockfile must be regenerated after any digest bump.

### RPM Lockfile Scope

`rpms.lock.yaml` is generated from `rpms.in.yaml`. It contains two kinds of
entries, and both are "tracked" for the purposes of this section:

1. The packages explicitly listed in `rpms.in.yaml` — currently
`ca-certificates`, `jq`, and `gzip`.
2. Their resolved transitive dependencies pulled in by the resolver
(for example `oniguruma`, which the lockfile carries as a dependency
of `jq`). These are not named in `rpms.in.yaml` but appear in
`rpms.lock.yaml` because the resolver had to pin them.

Together, "tracked packages" below means the union of (1) and (2): every RPM
that ends up in `rpms.lock.yaml`, whether requested directly or pulled in
transitively.

RPMs that ship inside the base image itself (for example `curl-minimal`,
`glib2`, `libcurl-minimal`, `libnghttp2`) are **not** tracked in the lockfile —
they are neither listed in `rpms.in.yaml` nor pulled in as a transitive
dependency of anything that is.

Consequence: when a UBI base image digest bump ships updates only to
base-image-bundled RPMs and no tracked package's available version changed
(neither an explicitly listed package nor any of its resolved transitive
dependencies), `hack/update-rpm-lock.sh` runs successfully but produces no
diff in `rpms.lock.yaml`. A commit that bumps the digest in the Dockerfiles
without touching `rpms.lock.yaml` is the expected outcome in that case, not
evidence that the lockfile was skipped.

### Review Guidance for UBI Bump PRs

On any PR that bumps the `ubi-minimal` digest:

- Do **not** flag "`rpms.lock.yaml` was not regenerated" as a finding solely
because the lockfile is unchanged. Regeneration is a no-op when no tracked
package's version changed, and that is the common case. Confirm the lockfile
was regenerated only by asking the author (or checking CI logs) — the diff
alone cannot prove it either way.
- If the concern is that a new base-image-bundled RPM should be tracked
explicitly, that is a separate change to `rpms.in.yaml`, not a bug in the
bump PR.

On `release-v*` branches, bump PRs may intentionally update only the production

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] intent-coherence

Issue #3503 proposed four documentation topics; the PR adds a fifth (release-branch nuance — bump PRs may intentionally skip the acceptance Dockerfile on release-v* branches) not enumerated in the issue but consistent with its stated goal ('prevent false-positive review findings') and plausibly a refinement of the 'reviewer guidance' topic.

Dockerfiles (`Dockerfile`, `Dockerfile.dist`) and skip the acceptance
Dockerfile, since acceptance test infrastructure is typically not backported.
The coordinated update set in `hack/ubi-base-image-bump.sh` applies to `main`;
a narrower scope on release branches is expected, not stale.

## Claude Code Skills

Skills live in `.claude/skills/<name>/SKILL.md`. They are **step-by-step executable workflows**
Expand Down
11 changes: 10 additions & 1 deletion renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,5 +2,14 @@
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"github>conforma/.github//config/renovate/renovate.json"
]
],
// Vulnerability/security fixes are already kept as standalone PRs and created
// immediately: Renovate internally forces `groupName: null` and ignores the
// daily `schedule` for vulnerability alerts via its built-in `force` block,
// which outranks user config — so an explicit ungrouping rule or a `schedule`
// override would be a no-op and is intentionally omitted.
// Here we only add labels so CVE-fix PRs are easy to spot and route.
"vulnerabilityAlerts": {
"labels": ["security", "renovate"]
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -571,14 +571,17 @@ spec:
imagePullPolicy: IfNotPresent
onError: continue # progress even if the step fails so we can see the debug logs
command: [sh, -c]
env:
- name: HOMEDIR
value: "$(params.HOMEDIR)"
args:
# Format the JSON output to wrap lines at 8000 characters per line.
# The report can get very large, so add some line breaks
# rather than print it as a single line. This makes it easier to render
# in the UI, easier to copy/paste, and less likely to cause problems
# with logging systems or other consumers of the data (assuming they
# correctly parse the full output).
- "jq . $(params.HOMEDIR)/report-json.json | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'"
- "jq . \"${HOMEDIR}/report-json.json\" | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'"

- name: summary
image: quay.io/conforma/cli:latest
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -475,14 +475,17 @@ spec:
imagePullPolicy: IfNotPresent
onError: continue # progress even if the step fails so we can see the debug logs
command: [sh, -c]
env:
- name: HOMEDIR
value: "$(params.HOMEDIR)"
args:
# Format the JSON output to wrap lines at 8000 characters per line.
# The report can get very large, so add some line breaks
# rather than print it as a single line. This makes it easier to render
# in the UI, easier to copy/paste, and less likely to cause problems
# with logging systems or other consumers of the data (assuming they
# correctly parse the full output).
- "jq . $(params.HOMEDIR)/report-json.json | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'"
- "jq . \"${HOMEDIR}/report-json.json\" | awk '{gsub(/^ +/, \"\"); acc += length; if (acc >= 8000) { printf \"\\n\"; acc=length } printf $0 }'"

- name: summary
computeResources:
Expand Down
Loading