OAPE-836: V1.42.3 Rebase openshift/main with upstream v1.42.3 - #82
OAPE-836: V1.42.3 Rebase openshift/main with upstream v1.42.3#82mytreya-rh wants to merge 22 commits into
Conversation
Bumps [pyasn1](https://github.com/pyasn1/pyasn1) from 0.6.2 to 0.6.3. - [Release notes](https://github.com/pyasn1/pyasn1/releases) - [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst) - [Commits](pyasn1/pyasn1@v0.6.2...v0.6.3) --- updated-dependencies: - dependency-name: pyasn1 dependency-version: 0.6.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.75.1 to 1.79.3. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.75.1...v1.79.3) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.79.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0. - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.5...v2.33.0) --- updated-dependencies: - dependency-name: requests dependency-version: 2.33.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#215) Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.5 to 46.0.6. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.5...46.0.6) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.40.0 to 1.43.0. - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.40.0...v1.43.0) --- updated-dependencies: - dependency-name: go.opentelemetry.io/otel/sdk dependency-version: 1.43.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#217) Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.6 to 46.0.7. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.6.3...2.7.0) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.7.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [idna](https://github.com/kjd/idna) from 3.11 to 3.15. - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md) - [Commits](kjd/idna@v3.11...v3.15) --- updated-dependencies: - dependency-name: idna dependency-version: '3.15' dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#225) Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.7 to 48.0.1. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...48.0.1) --- updated-dependencies: - dependency-name: cryptography dependency-version: 48.0.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
…e to reduce cve footprint (#227) Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps ubi9/ubi-minimal from 9.7 to 9.8. --- updated-dependencies: - dependency-name: ubi9/ubi-minimal dependency-version: '9.8' dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Update go.mod need 1.26.1. version to fix CVE-2026-25679,CVE-2026-27139,CVE-2026-27142 Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> * Update go.mod Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> * Update go.mod Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> --------- Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> Co-authored-by: Preethi-Ps <nannetpreethi@gmail.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
|
@mytreya-rh: This pull request references OAPE-836 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mytreya-rh The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughThe change adds a six-stage OpenShift requirements generator, integrates it into the requirements image, refreshes generated dependencies and container tooling, updates Go and release versions, changes Galaxy metadata endpoints, and upgrades workflow checkout actions. ChangesRequirements and release refresh
Estimated code review effort: 5 (Critical) | ~120 minutes Suggested reviewers: Sequence Diagram(s)sequenceDiagram
participant Dockerfile_requirements
participant generate_requirements_py
participant pipenv
participant Safety
participant pip_find_builddeps_py
participant pip_compile
participant requirements_artifacts
Dockerfile_requirements->>generate_requirements_py: invoke six-stage generation
generate_requirements_py->>pipenv: resolve and update runtime packages
generate_requirements_py->>Safety: scan runtime and build requirements
generate_requirements_py->>pip_find_builddeps_py: collect build dependencies
pip_find_builddeps_py-->>generate_requirements_py: return build constraints
generate_requirements_py->>pip_compile: compile phased requirements
generate_requirements_py->>requirements_artifacts: write requirements files and Pipfile.lock
Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 error)
✅ Passed checks (14 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 14
🧹 Nitpick comments (5)
images/ansible-operator/Pipfile (1)
8-11: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winPin the build-tool installs exactly
pip~=26.1.2and the unpinnedpip-auditin both Dockerfiles can drift; use exact versions there. ThePipfileentries already resolve to exact versions throughPipfile.lock, so they don’t need==pins.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@images/ansible-operator/Pipfile` around lines 8 - 11, Pin the build-tool dependencies exactly in both Dockerfiles: update pip to 26.1.2 and assign an exact version to pip-audit in images/ansible-operator/Dockerfile lines 29-30 and images/ansible-operator/pipfile.Dockerfile lines 23-24. No change is required in images/ansible-operator/Pipfile lines 8-11 because its lockfile already resolves those entries exactly.Source: Path instructions
openshift/hack/generate_requirements.py (3)
452-468: 🎯 Functional Correctness | 🔵 Trivial | 💤 Low valueGap heuristic splits on patch-only differences.
When every consecutive gap is
0(e.g. resolved versions8.1.0and8.1.2),max_gapnever exceeds0,split_afterstays atunique[0], and the group is split even though no major/minor conflict exists. The recursion re-validates each sub-group, so the result is only extra phases rather than a wrong one — but requiringmax_gap > 0before splitting would avoid the spurious phase.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 452 - 468, Update the gap-splitting logic around split_after and max_gap so it returns no split when the largest major/minor gap is zero, including patch-only differences. Only compute and return the older group when max_gap is greater than zero; preserve the existing split behavior for genuine major/minor gaps.
203-207: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win
_min_safe_versionpicks the last upper bound, not the tightest.For multi-clause specs (Safety often emits ranges joined by
||, e.g.<1.9 || >=2.0,<2.1), the last<Xmatch is the newest bound, so the inferred "min safe version" can silently overshoot or undershoot. Selecting the maximum bound withpackaging.version.Versionmakes the intent explicit and matches the docstring.♻️ Proposed refactor
- # Find the tightest upper bound: the version just after <X - best: str | None = None - for m in re.finditer(r"<([0-9][0-9a-zA-Z._-]*)", affected_spec): - best = m.group(1) # last match wins (most restrictive) - return best + # Pick the highest upper bound across all clauses so the resulting + # ">=best" constraint clears every affected range. + from packaging.version import InvalidVersion, Version + + best: str | None = None + for m in re.finditer(r"<([0-9][0-9a-zA-Z._-]*)", affected_spec): + cand = m.group(1) + if best is None: + best = cand + continue + try: + if Version(cand) > Version(best): + best = cand + except InvalidVersion: + best = cand + return best🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 203 - 207, Update _min_safe_version to compare every matched upper-bound version using packaging.version.Version and retain the maximum bound rather than relying on the last regex match. Return the selected version in the existing string format, preserving None when no upper bounds are found.
625-629: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueEvery committed lockfile header now records absolute
/requirements*.inpaths.stage2_runtime_txtwrites the compile input intoout_dirspecifically to keep pip-compile's# viaannotations relative-looking, but the container invokes the generator with the default--output-dir .at/, so all three regenerated files carry/requirements-*.inannotations instead of the previous relative form. Harmless for pip, but it inflates the diff on every regeneration.
openshift/hack/generate_requirements.py#L625-L629: either write the.infiles relative to the process CWD, or update the comment to reflect that the annotation path follows--output-dir.openshift/requirements-build.txt#L5-L6: regenerate once the output directory is a real subdirectory so annotations return to the relative form.openshift/requirements-pre-build.txt#L5-L6: same regeneration applies to this header and its# vialines.openshift/requirements.txt#L5-L6: same regeneration applies to this header and its# vialines.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 625 - 629, The stage2_runtime_txt path setup around compile_in and out_txt currently produces absolute # via annotations when --output-dir is /. Make the compile input path relative to the process CWD (or update the comment to accurately document --output-dir-dependent behavior), then regenerate openshift/requirements-build.txt:5-6, openshift/requirements-pre-build.txt:5-6, and openshift/requirements.txt:5-6 using a real subdirectory so their headers and # via lines use relative paths.openshift/hack/generate_requirements.md (1)
27-32: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueAdd languages to fenced code blocks (markdownlint MD040).
Seven fenced blocks (Lines 27, 60, 121, 183, 216, 242, 288) have no language specified.
textis fine for the ASCII diagrams.Also applies to: 60-80, 121-125
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.md` around lines 27 - 32, Add the `text` language identifier to the seven unlabeled fenced code blocks in generate_requirements.md, including the blocks around the listed sections, while preserving their existing diagram and content text.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Line 28: Pin every actions/checkout invocation to a full immutable commit SHA
instead of the mutable `@v7` tag: update .github/workflows/release.yml at lines
28-28 and 66-66, .github/workflows/test-ansible.yml at lines 10-10 and 23-23,
.github/workflows/test-sanity.yml at line 10, and .github/workflows/unit.yml at
line 10.
In @.github/workflows/test-ansible.yml:
- Around line 10-12: Add persist-credentials: false to every actions/checkout
step in .github/workflows/test-ansible.yml at lines 10-12 and 23-25,
.github/workflows/test-sanity.yml at lines 10-12, and .github/workflows/unit.yml
at lines 10-12; no other workflow behavior needs changing.
In `@go.mod`:
- Line 110: Update the google.golang.org/grpc dependency in go.mod from v1.79.3
to v1.82.1 or later, and synchronize related module checksums or dependency
metadata so the module build list no longer includes the vulnerable version.
In `@images/ansible-operator/pipfile.Dockerfile`:
- Line 1: Add a non-root user in the basebuilder image, grant that user write
access to /tmp/pip-airlock, and configure the image to run as that user so the
ENTRYPOINT cp operation does not create root-owned Pipfile.lock files.
In `@openshift/Dockerfile.requirements`:
- Around line 33-34: Update the documentation describing hardcoded package
assumptions: in openshift/Dockerfile.requirements lines 33-34, replace the
cachi2-specific wheel pin statement with a note that build-isolation pins are
auto-discovered from package metadata; in
openshift/hack/generate_requirements.py lines 5-7, remove “and cachi2-specific
pins” from the module docstring while leaving the script behavior unchanged.
In `@openshift/hack/generate_requirements.md`:
- Line 188: Update the step-count descriptions in the requirements-generation
documentation: change “five strategies” to “six strategies” near the
recursion-level list and “three-step process” to “four-step process” near the
later numbered list, without changing the steps themselves.
In `@openshift/hack/generate_requirements.py`:
- Around line 882-883: Remove the unnecessary f-string prefixes from the literal
string fragments in the requirement-generation output, including the fragments
near the auto-detected build-isolation pins and the corresponding locations
around lines 1001 and 1236. Preserve the existing concatenation and
interpolation for strings that still contain placeholders.
- Around line 230-239: Update the vulnerability parsing at this path and the
re-check around the second parse site to use the combined check.stdout and
check.stderr streams, matching Stage 5’s _strip_ansi handling. Preserve the
existing warning and auto-fix behavior while ensuring reports emitted on stderr
are parsed and processed.
- Around line 992-999: Change the deferred-package handling around the mapped
phase loop so `later_pkgs` constraints are accumulated when
`requirements-build.in` is not yet available, instead of being dropped. After
the loop has produced the build requirements, append all deferred specs and run
the same `_pip_compile`, `_normalize_quirks`, and `_comment_out` post-processing
used for the normal build output, ensuring RPM-installed packages remain
commented out.
- Around line 1062-1078: Update the Safety invocation loop around safety_cmd so
missing executables are caught as FileNotFoundError and the next command form is
attempted. Remove the premature stderr-based break and only stop when the
command executes successfully or produces a non-missing-command result, while
preserving the existing return-code handling and artifact generation flow.
In `@openshift/hack/rebase_upstream.sh`:
- Around line 49-52: Update the existing-branch path in the rebase_work_branch
reuse logic to ensure the checked-out branch contains the refreshed
rebase_branch before continuing. Merge the updated base into the reused branch,
or perform an ancestry check and abort with a clear message when it is not based
on the refreshed target.
- Around line 50-54: Update the existing-branch path around rebase_work_branch
so git checkout failure aborts the script immediately, matching the failure
handling in the branch-creation path. Preserve the current success behavior and
ensure no merge or commit proceeds when checkout fails.
In `@openshift/requirements-build.txt`:
- Around line 56-74: Update the pinned setuptools version in the requirements
file from 82.0.1 to a patched release that addresses the published advisory,
keeping the existing unsafe-package entry and formatting intact.
In `@openshift/requirements.txt`:
- Around line 33-36: Update the pinned runtime dependency set in
requirements.txt by restoring the rsa package required by google-auth==2.55.0,
using the compatible rsa>=3.1.4,<5 constraint and retaining the existing
generated dependency annotations for the google-auth dependency chain.
---
Nitpick comments:
In `@images/ansible-operator/Pipfile`:
- Around line 8-11: Pin the build-tool dependencies exactly in both Dockerfiles:
update pip to 26.1.2 and assign an exact version to pip-audit in
images/ansible-operator/Dockerfile lines 29-30 and
images/ansible-operator/pipfile.Dockerfile lines 23-24. No change is required in
images/ansible-operator/Pipfile lines 8-11 because its lockfile already resolves
those entries exactly.
In `@openshift/hack/generate_requirements.md`:
- Around line 27-32: Add the `text` language identifier to the seven unlabeled
fenced code blocks in generate_requirements.md, including the blocks around the
listed sections, while preserving their existing diagram and content text.
In `@openshift/hack/generate_requirements.py`:
- Around line 452-468: Update the gap-splitting logic around split_after and
max_gap so it returns no split when the largest major/minor gap is zero,
including patch-only differences. Only compute and return the older group when
max_gap is greater than zero; preserve the existing split behavior for genuine
major/minor gaps.
- Around line 203-207: Update _min_safe_version to compare every matched
upper-bound version using packaging.version.Version and retain the maximum bound
rather than relying on the last regex match. Return the selected version in the
existing string format, preserving None when no upper bounds are found.
- Around line 625-629: The stage2_runtime_txt path setup around compile_in and
out_txt currently produces absolute # via annotations when --output-dir is /.
Make the compile input path relative to the process CWD (or update the comment
to accurately document --output-dir-dependent behavior), then regenerate
openshift/requirements-build.txt:5-6, openshift/requirements-pre-build.txt:5-6,
and openshift/requirements.txt:5-6 using a real subdirectory so their headers
and # via lines use relative paths.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 29944b7a-ce45-4d4b-a48f-d75ab87228fb
⛔ Files ignored due to path filters (255)
go.sumis excluded by!**/*.sumimages/ansible-operator/Pipfile.lockis excluded by!**/*.lockopenshift/Pipfile.lockis excluded by!**/*.lockvendor/cel.dev/expr/BUILD.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/MODULE.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/checked.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/eval.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/explain.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/syntax.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/value.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/.gitignoreis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/core_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/command/program.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/main.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/ginkgo.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/outline.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/run/run_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/watch/watch_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo_t_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/helpergo_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/global/init.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/suite.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/testingtproxy/testing_t_proxy.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/reporters/default_reporter.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/config.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/flags.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/version.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/format/format.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/gomega_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_a_slice_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_an_array_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/types/types.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/.golangci.ymlis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/Makefileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/RELEASING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/encoder.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/hash.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/internal/attribute.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/kv.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/type_string.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/value.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/baggage/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/dependencies.Dockerfileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/errorhandler/errorhandler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/handler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/state.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/meter.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/trace_context.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/requirements.txtis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/internal/x/features.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/builtin.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/config.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/container.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/env.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id_readfile.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/os.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/process.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/resource.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/simple_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/tracer.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/provider.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/sampling.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/span.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/attribute_group.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/doc.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/error_type.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/exception.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/otelconv/metric.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/schema.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/auto.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/trace.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/tracestate.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/versions.yamlis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/node.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/nodetype_string.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_conn_pool.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go127.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_random.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/pre_go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/punycode.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpsfv/httpsfv.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/deviceauth.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/oauth2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/pkce.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/token.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/singleflight/singleflight.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/plan9/syscall_plan9.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_signed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_unsigned.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkall.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_solaris.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_unix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/dll_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/registry/key.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/security_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/edge/edge.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/cursor.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/inspector.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/golist.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases_go122.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/core/event.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/keys/keys.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/label/label.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iexport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iimport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/ureader.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gocommand/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/fix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/mod.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/source_modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/directories.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/index.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/lookup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/symbols.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/pkgbits/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/deps.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/coretype.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/free.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/types.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/versions/features.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/balancer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirst.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirstleaf/pickfirstleaf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/roundrobin/roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/subconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/binarylog/grpc_binarylog_v1/binarylog.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/credentials.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/tls.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/encoding.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/gzip/gzip.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/proto/proto.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metricregistry.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metrics.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health_grpc.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/interceptor.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/gracefulswitch/gracefulswitch.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/weight/weight.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/buffer/unbounded.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/channelz/trace.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/envconfig.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/xds.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/experimental.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/idle/idle.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/delegatingresolver/delegatingresolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/dns/dns_resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/metrics_recorder_list.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/stats.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/client_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/controlbuf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/flowcontrol.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/handler_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_client.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/server_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/transport.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_pool.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_slice.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffers.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/preloader.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver/resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/rpc_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_lazy.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/version/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/proto.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (24)
.github/workflows/release.yml.github/workflows/test-ansible.yml.github/workflows/test-sanity.yml.github/workflows/unit.ymlMakefilego.modimages/ansible-operator/Dockerfileimages/ansible-operator/Pipfileimages/ansible-operator/pipfile.Dockerfileinternal/version/version.goopenshift/Dockerfile.requirementsopenshift/hack/generate_requirements.mdopenshift/hack/generate_requirements.pyopenshift/hack/rebase_upstream.shopenshift/release/ansible/ansible_collections/cloud.common-3.0.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.docker-3.12.1.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.library_inventory_filtering_v1-1.1.5.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/kubernetes.core-3.2.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/operator_sdk.util-0.5.0.info/GALAXY.ymlopenshift/requirements-build.txtopenshift/requirements-build1.txtopenshift/requirements-pre-build.txtopenshift/requirements.txttestdata/memcached-molecule-operator/Makefile
| google-auth==2.55.0 | ||
| # via | ||
| # -r requirements.in | ||
| # -r /requirements.in | ||
| # kubernetes |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🌐 Web query:
google-auth 2.55.0 Python dependencies rsa requirement
💡 Result:
In google-auth version 2.55.0, the rsa library is listed as a required dependency, with the version constraint defined as >=3.1.4 and <5 [1][2]. While google-auth has transitioned to using the cryptography library as its primary backend for RSA operations [3], rsa remained a required dependency in version 2.55.0 to maintain backward compatibility and support existing functionality [4][3][2]. The library uses internal wrapper classes (such as RSASigner and RSAVerifier) that can leverage either the cryptography library or the rsa library [5][3]. In subsequent development, the project has aimed to reduce and eventually remove this hard dependency on rsa, moving it toward optional status in newer versions of the library [3][6][2].
Citations:
- 1: https://pypi.org/project/google-auth/2.55.0/
- 2: https://data.gpo.zugaina.org/gentoo/dev-python/google-auth/google-auth-2.55.0.ebuild
- 3: feat: add cryptography as required dependency googleapis/google-auth-library-python#1929
- 4: https://github.com/GoogleCloudPlatform/google-auth-library-python/blob/master/setup.py
- 5: https://googleapis.dev/python/google-auth/latest/reference/google.auth.crypt.rsa.html
- 6: https://pypi.org/project/google-auth/
🏁 Script executed:
set -euo pipefail
printf '\n[1] locate google-auth and rsa entries in openshift/requirements.txt\n'
rg -n '^(google-auth==|rsa==|pyasn1==|pyasn1-modules==)' openshift/requirements.txt || true
printf '\n[2] show the surrounding block around google-auth\n'
python3 - <<'PY'
from pathlib import Path
p = Path('openshift/requirements.txt')
lines = p.read_text().splitlines()
for i, line in enumerate(lines, 1):
if line.startswith('google-auth==') or line.startswith('rsa=='):
start = max(1, i-6)
end = min(len(lines), i+8)
print(f'\n--- lines {start}-{end} around line {i} ---')
for j in range(start, end+1):
print(f'{j:4}: {lines[j-1]}')
PY
printf '\n[3] check whether rsa appears anywhere in the file at all\n'
python3 - <<'PY'
from pathlib import Path
text = Path('openshift/requirements.txt').read_text()
print('rsa present:' , 'rsa==' in text or '\nrsa\n' in text or ' rsa' in text)
PYRepository: openshift/ansible-operator-plugins
Length of output: 834
Restore rsa to the google-auth runtime set. google-auth==2.55.0 still requires rsa>=3.1.4,<5, but rsa is missing from openshift/requirements.txt while its sibling deps are still pinned. A hermetic install will fail when google-auth is imported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/requirements.txt` around lines 33 - 36, Update the pinned runtime
dependency set in requirements.txt by restoring the rsa package required by
google-auth==2.55.0, using the compatible rsa>=3.1.4,<5 constraint and retaining
the existing generated dependency annotations for the google-auth dependency
chain.
There was a problem hiding this comment.
We are not seeing any failure
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '%s\n' '[1] Locate rsa and dependency-install references'
rg -n -i -C 3 '(^rsa([<=>!~ ]|$)|\brsa\b|RPM_INSTALLED|--no-deps|requirements\.txt)' \
openshift/hack/generate_requirements.py \
openshift/Dockerfile.requirements \
images/ansible-operator/Dockerfile \
openshift 2>/dev/null || true
printf '%s\n' '[2] Map the generator before reading relevant sections'
ast-grep outline openshift/hack/generate_requirements.py --items all --type function,variable --match 'RPM_INSTALLED|stage2_runtime_txt|stage6_verify_completeness' || true
printf '%s\n' '[3] Show the generator exclusion and runtime-output logic'
rg -n -A 80 -B 12 'RPM_INSTALLED|def stage2_runtime_txt|def stage6_verify_completeness' \
openshift/hack/generate_requirements.py || true
printf '%s\n' '[4] Show how generated requirements are installed or exported'
cat -n openshift/Dockerfile.requirements | sed -n '1,220p'Length of output: 113996
🏁 Script executed:
#!/bin/bash
set -euo pipefail
python3 - <<'PY'
import json
from urllib.request import urlopen
url = "https://pypi.org/pypi/google-auth/2.55.0/json"
with urlopen(url, timeout=20) as response:
payload = json.load(response)
requirements = payload["info"].get("requires_dist") or []
print("google-auth version:", payload["info"]["version"])
print("Requires-Dist entries:")
for requirement in requirements:
print(" -", requirement)
print("rsa requirement present:", any(item.lower().startswith("rsa") for item in requirements))
PYLength of output: 3130
What are the exact `Requires-Dist` dependencies listed in the PyPI metadata for `google-auth` version `2.55.0`? In particular, does that exact release require the `rsa` package?
You are interacting with an AI system.
|
/assign |
chiragkyal
left a comment
There was a problem hiding this comment.
Thanks a lot for the automation script. Adding few comments/queries:
- Can we have a single commit with the downstream requirement changes? Currently, we have them in both 5c3c790 and d822aff commits.
- I think the order of the commit should be:
- The new conflict resolution script and steps
- Use the above script to do the rebase
- Downstream specific requirement files
- If we follow the above steps, can we avoid 1703a4c commit?
There was a problem hiding this comment.
Why do we need this redundant Pipfile.lock?
There was a problem hiding this comment.
Good catch, and you're right that it's currently byte-identical to images/ansible-operator/Pipfile.lock. This is intentional though, not redundant: openshift/Pipfile.lock is the artifact exported by Stage 1's CVE auto-fix (pipenv update <pkg> on top of the upstream lock file), so it's expected to diverge over time as new CVEs get fixed downstream between upstream rebases — waiting for every fix to land upstream first isn't practical given the CVE volume, and it naturally re-syncs at each rebase anyway. I've added an explicit "Why openshift/Pipfile.lock Can Differ..." section to generate_requirements.md and strengthened the Dockerfile.requirements comment block to spell this out, so it's discoverable next time someone asks the same question.
There was a problem hiding this comment.
Thanks for the explanation. Wondering if we should keep a copy of Pipfile as well, or not, to make it consistent with the updated Pipfile.lock?
|
|
||
| VOLUME /tmp/requirements | ||
| ENTRYPOINT ["cp", "./requirements.txt", "./requirements-build.txt", "./requirements-build1.txt", "./requirements-pre-build.txt", "/tmp/requirements/"] | ||
| ENTRYPOINT ["cp", "./requirements.txt", "./requirements-build.txt", "./requirements-build1.txt", "./requirements-pre-build.txt", "./Pipfile.lock", "/tmp/requirements/"] |
There was a problem hiding this comment.
Same as above, do we really need Pipfile.lock for installing the requirements? To my understanding, it should be the same as the upstream one.
There was a problem hiding this comment.
Same rationale as the Pipfile.lock comment: it isn't guaranteed to always match the upstream one, by design — Stage 1's CVE auto-fix can bump pins in the exported copy ahead of upstream. I've expanded the comment block right above this line to call that out explicitly.
| pipenv run pip freeze --all # get all pinned versions | ||
| ``` | ||
|
|
||
| ### CVE Auto-Fix for Runtime Packages |
There was a problem hiding this comment.
It might cause bumping the package version only in downstream, whereas the fix should land in upstream first.
There was a problem hiding this comment.
Agreed this is a real tradeoff, but given how frequently CVEs come in, waiting on an upstream-first fix for every pin bump would create an unacceptable backlog, and any divergence resets naturally at the next rebase (since we start fresh from upstream's Pipfile each time). I've documented this reasoning explicitly in the new rationale section rather than changing the behavior.
| identifies the culprit, which becomes the earlier group. | ||
|
|
||
| **Step 6 — Give up** | ||
| If no split can be found, the whole group is kept as one phase and a warning is |
There was a problem hiding this comment.
Shouldn't we error out and fail the script instead of just warning which we might overlook
There was a problem hiding this comment.
Valid gap, thanks for flagging it. Both this CVE-auto-fix path (Stage 1) and the equivalent build-dep CVE scan (Stage 5) now sys.exit(1) with a detailed report when a CVE can't be auto-fixed, instead of only printing a warning — so make check-requirements (and CI) will fail loudly instead of silently passing with an unresolved known CVE buried in the logs.
There was a problem hiding this comment.
Now that the script will fail if the CVE cannot be auto-fixed, are there any recommended steps for how it should be manually investigated/fixed?
There was a problem hiding this comment.
At the end of the requirement generation process, can we add a verification step to ensure that all four requirement files include every package defined in the Pipfile/Pipfile.lock? The verification should also confirm that no packages are missing, omitted or commented out.
I think this will be a valuable sanity check.
There was a problem hiding this comment.
Added — there's now a Stage 6 (stage6_verify_completeness()) that checks every package pinned in Pipfile.lock is correctly represented in requirements.txt: present and active, unless it's an RPM-installed package (must be commented out) or one of pip-compile's own reserved "unsafe" packages (pip/setuptools/distribute — these are unconditionally dropped by pip-compile itself when compiled without --allow-unsafe, which is how Stage 2 compiles requirements.txt, so their absence there is correct rather than a bug). It fails loudly listing any missing/miscommented package by name. Documented in the new "Stage 6 — Completeness Verification" section. I validated it locally against the real Pipfile.lock/requirements.txt and it correctly passes on the current committed state and correctly caught an edge case (pip itself) during development that I then had to special-case.
There was a problem hiding this comment.
Do you think we should validate that from CI as well? If in the long run we want to make this repo self-sustaining, having this verification in CI would help cross-verify instead of a local dependency.
There was a problem hiding this comment.
In our envisioned self-sustain mode, the script as it is will be called from https://github.com/openshift/ansible-operator-plugins/blob/main/openshift/hack/rebase_upstream.sh through a rebasebot, and any other periodic job which will attempt to fix CVEs. Thus the invoking job itself will fail. So, i feel we need to not check it again as a standalone job.
d822aff to
7115916
Compare
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
|
Thanks for the thorough review, @chiragkyal! I've addressed all of the inline comments (replied individually in each thread) and, for the top-level commit-hygiene request, restructured the branch history:
New commit sequence:
This was a pure history rewrite — I verified the final tree is byte-identical to the previous PR head everywhere except the script/doc files touched by the review fixes above (and the now-unnecessary |
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (1)
openshift/Dockerfile.requirements (1)
50-52: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winSecurity Misconfiguration (CWE-494): Download of Code Without Integrity Check
Reachability: Internal
Pin the requirement-generation inputs.
Pin
pip-toolsto an exact version. Fetchpip_find_builddeps.pyat a commit SHA and verify its checksum before execution.openshift/Makefilecompares generated files, andopenshift/install-ansible.shconsumes those files. Floating inputs can change the artifacts or execute changed upstream code during generation.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/Dockerfile.requirements` around lines 50 - 52, Update the requirement-generation RUN step to pin pip-tools to an exact version, download pip_find_builddeps.py from a fixed commit SHA, and verify the downloaded file against an expected checksum before running it. Keep generate_requirements.py and the existing generation flow intact, ensuring all inputs used to produce the requirements artifacts are immutable and verified.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/test-ansible.yml:
- Around line 10-12: Pin every changed actions/checkout step to a reviewed
40-character commit SHA instead of the mutable v7 tag: update
.github/workflows/test-ansible.yml lines 10-12 and 23-25,
.github/workflows/test-sanity.yml lines 10-12, and .github/workflows/unit.yml
lines 10-12, preserving each step’s existing with configuration.
In `@images/ansible-operator/pipfile.Dockerfile`:
- Around line 23-24: Update the bootstrap install commands in the Dockerfile to
pin exact versions for pip, pipenv, and pip-audit, and add reviewed hash
constraints for each package. Ensure the subsequent pipenv lock flow remains
unchanged while no unpinned or range-based bootstrap dependency remains.
In `@openshift/hack/generate_requirements.py`:
- Around line 239-241: The documentation comments for auto_fix_cves still
describe CVE remediation as non-blocking. In
openshift/hack/generate_requirements.py:239-241, update the third docstring
outcome to state that remediation guidance is printed and the function exits
non-zero; in openshift/hack/generate_requirements.py:611-613, replace the “Never
blocks requirements generation” note with the behavior that the call exits
non-zero when a pip-managed CVE cannot be auto-fixed.
---
Nitpick comments:
In `@openshift/Dockerfile.requirements`:
- Around line 50-52: Update the requirement-generation RUN step to pin pip-tools
to an exact version, download pip_find_builddeps.py from a fixed commit SHA, and
verify the downloaded file against an expected checksum before running it. Keep
generate_requirements.py and the existing generation flow intact, ensuring all
inputs used to produce the requirements artifacts are immutable and verified.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 799734e2-96fa-4174-a560-8a18c3fe73ba
⛔ Files ignored due to path filters (255)
go.sumis excluded by!**/*.sumimages/ansible-operator/Pipfile.lockis excluded by!**/*.lockopenshift/Pipfile.lockis excluded by!**/*.lockvendor/cel.dev/expr/BUILD.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/MODULE.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/checked.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/eval.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/explain.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/syntax.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/value.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/.gitignoreis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/core_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/command/program.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/main.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/ginkgo.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/outline.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/run/run_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/watch/watch_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo_t_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/helpergo_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/global/init.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/suite.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/testingtproxy/testing_t_proxy.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/reporters/default_reporter.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/config.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/flags.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/version.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/format/format.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/gomega_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_a_slice_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_an_array_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/types/types.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/.golangci.ymlis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/Makefileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/RELEASING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/encoder.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/hash.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/internal/attribute.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/kv.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/type_string.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/value.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/baggage/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/dependencies.Dockerfileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/errorhandler/errorhandler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/handler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/state.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/meter.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/trace_context.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/requirements.txtis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/internal/x/features.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/builtin.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/config.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/container.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/env.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id_readfile.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/os.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/process.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/resource.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/simple_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/tracer.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/provider.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/sampling.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/span.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/attribute_group.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/doc.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/error_type.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/exception.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/otelconv/metric.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/schema.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/auto.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/trace.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/tracestate.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/versions.yamlis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/node.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/nodetype_string.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_conn_pool.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go127.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_random.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/pre_go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/punycode.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpsfv/httpsfv.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/deviceauth.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/oauth2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/pkce.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/token.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/singleflight/singleflight.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/plan9/syscall_plan9.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_signed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_unsigned.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkall.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_solaris.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_unix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/dll_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/registry/key.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/security_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/edge/edge.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/cursor.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/inspector.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/golist.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases_go122.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/core/event.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/keys/keys.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/label/label.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iexport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iimport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/ureader.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gocommand/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/fix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/mod.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/source_modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/directories.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/index.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/lookup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/symbols.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/pkgbits/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/deps.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/coretype.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/free.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/types.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/versions/features.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/balancer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirst.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirstleaf/pickfirstleaf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/roundrobin/roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/subconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/binarylog/grpc_binarylog_v1/binarylog.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/credentials.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/tls.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/encoding.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/gzip/gzip.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/proto/proto.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metricregistry.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metrics.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health_grpc.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/interceptor.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/gracefulswitch/gracefulswitch.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/weight/weight.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/buffer/unbounded.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/channelz/trace.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/envconfig.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/xds.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/experimental.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/idle/idle.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/delegatingresolver/delegatingresolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/dns/dns_resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/metrics_recorder_list.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/stats.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/client_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/controlbuf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/flowcontrol.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/handler_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_client.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/server_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/transport.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_pool.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_slice.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffers.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/preloader.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver/resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/rpc_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_lazy.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/version/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/proto.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (23)
.github/workflows/release.yml.github/workflows/test-ansible.yml.github/workflows/test-sanity.yml.github/workflows/unit.ymlMakefilego.modimages/ansible-operator/Dockerfileimages/ansible-operator/Pipfileimages/ansible-operator/pipfile.Dockerfileinternal/version/version.goopenshift/Dockerfile.requirementsopenshift/hack/generate_requirements.mdopenshift/hack/generate_requirements.pyopenshift/release/ansible/ansible_collections/cloud.common-3.0.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.docker-3.12.1.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.library_inventory_filtering_v1-1.1.5.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/kubernetes.core-3.2.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/operator_sdk.util-0.5.0.info/GALAXY.ymlopenshift/requirements-build.txtopenshift/requirements-build1.txtopenshift/requirements-pre-build.txtopenshift/requirements.txttestdata/memcached-molecule-operator/Makefile
🚧 Files skipped from review as they are similar to previous changes (15)
- testdata/memcached-molecule-operator/Makefile
- openshift/release/ansible/ansible_collections/operator_sdk.util-0.5.0.info/GALAXY.yml
- openshift/release/ansible/ansible_collections/cloud.common-3.0.0.info/GALAXY.yml
- Makefile
- .github/workflows/release.yml
- images/ansible-operator/Pipfile
- openshift/requirements.txt
- internal/version/version.go
- openshift/requirements-build1.txt
- openshift/release/ansible/ansible_collections/community.docker-3.12.1.info/GALAXY.yml
- images/ansible-operator/Dockerfile
- openshift/release/ansible/ansible_collections/kubernetes.core-3.2.0.info/GALAXY.yml
- openshift/release/ansible/ansible_collections/community.library_inventory_filtering_v1-1.1.5.info/GALAXY.yml
- openshift/requirements-build.txt
- openshift/requirements-pre-build.txt
7115916 to
4798c31
Compare
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
|
The This happens because pip-tools relies on pip's internal, unstable Fixed by pinning both to a tested-compatible pair ( |
|
/test sanity |
4798c31 to
7e914b7
Compare
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
There was a problem hiding this comment.
♻️ Duplicate comments (1)
openshift/hack/generate_requirements.py (1)
1017-1024: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy liftThe deferred build-phase recompile still skips post-processing.
The previous review thread is marked as addressed, but the defect is still present in this code:
mappedis iterated inpre_build → build1 → buildorder. When the failing phase ispre_buildorbuild1,requirements-build.indoes not exist yet,build_in.exists()isFalse, and every constraint inlater_pkgsis dropped with no warning.- Line 1024 writes
requirements-build.txtdirectly. The post-processing at lines 1039-1042 applies totxt_path, not tobuild_txt. RPM-installed packages (cryptography,cffi,pycparser,maturin) therefore stay uncommented inrequirements-build.txt, and the hermetic build tries to pip-install them.🐛 Minimum fix
build_in = out_dir / "requirements-build.in" build_txt = out_dir / "requirements-build.txt" + extra = [s for p in later_pkgs for s in pkg_constraints.get(p, [])] if build_in.exists(): existing = build_in.read_text() - extra = [s for p in later_pkgs for s in pkg_constraints.get(p, [])] build_in.write_text(existing + "\n".join(extra) + "\n") - _pip_compile(build_in, build_txt, ["--allow-unsafe"]) + if _pip_compile(build_in, build_txt, ["--allow-unsafe"])[0]: + c = _comment_out( + _normalize_quirks(build_txt.read_text()), rpm_norms + ) + build_txt.write_text(c) + elif extra: + print( + " WARNING: requirements-build.in not written yet;" + f" dropping build deps for {sorted(later_pkgs)}.", + file=sys.stderr, + )🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 1017 - 1024, Update the deferred build-phase handling around mapped, later_pkgs, and _pip_compile so constraints are retained when requirements-build.in does not yet exist by creating or initializing the file before appending them. After compiling build_txt, apply the same post-processing used for txt_path so RPM-installed packages are commented out in requirements-build.txt before the hermetic build consumes it.
🧹 Nitpick comments (3)
.github/workflows/test-ansible.yml (1)
10-12: 🔒 Security & Privacy | 🔵 Trivial | 💤 Low valueConsider
persist-credentials: falsein the checkout steps.The jobs do not push to the repository. They only build and run tests. Disable credential persistence so the token is not written to
.git/configfor later steps.🔒 Proposed change
- uses: actions/checkout@v7 with: fetch-depth: 0 + persist-credentials: falseAlso applies to lines 23-25.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/test-ansible.yml around lines 10 - 12, Update both checkout steps using actions/checkout@v7 to set persist-credentials to false alongside fetch-depth, ensuring the repository token is not persisted in .git/config.Source: Linters/SAST tools
openshift/hack/generate_requirements.py (1)
531-532: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueTemp file names can collide between sibling recursion groups.
split_{_depth}_{len(packages)}is not unique. Two sibling groups at the same depth with the same package count write the same.inand.txtfiles. Execution is sequential, so the result is currently correct, but the collision is fragile. The hardcoded_depth=10at line 1002 exists for the same reason.Consider a monotonic counter or
tempfile.mkstemp(dir=tmp)for these intermediate files.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 531 - 532, Make the intermediate filenames created in the recursive package-splitting flow unique across sibling groups by replacing the depth/package-count naming in merged_in and merged_out with a monotonic counter or tempfile-based allocation within tmp. Also remove the hardcoded _depth=10 workaround and pass or derive the actual recursion depth consistently through the relevant generation function.images/ansible-operator/pipfile.Dockerfile (1)
24-26: 🩺 Stability & Availability | 🔵 Trivial | 🏗️ Heavy liftKeep vulnerability scanning consistent.
pipenv auditis valid inpipenv==2026.6.2and invokespip-audit, so the Dockerfile commands are valid.generate_requirements.pystill uses the older Safety-basedpipenv checkpath and parses Safety output. Migrate it topipenv auditwith a compatible parser, or document the intentional difference.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@images/ansible-operator/pipfile.Dockerfile` around lines 24 - 26, Update generate_requirements.py to use pipenv audit instead of the legacy Safety-based pipenv check flow, and revise its vulnerability-output parsing to handle pip-audit results consistently with the Dockerfile’s pipenv audit command; alternatively, document the intentional divergence if preserving the existing behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Duplicate comments:
In `@openshift/hack/generate_requirements.py`:
- Around line 1017-1024: Update the deferred build-phase handling around mapped,
later_pkgs, and _pip_compile so constraints are retained when
requirements-build.in does not yet exist by creating or initializing the file
before appending them. After compiling build_txt, apply the same post-processing
used for txt_path so RPM-installed packages are commented out in
requirements-build.txt before the hermetic build consumes it.
---
Nitpick comments:
In @.github/workflows/test-ansible.yml:
- Around line 10-12: Update both checkout steps using actions/checkout@v7 to set
persist-credentials to false alongside fetch-depth, ensuring the repository
token is not persisted in .git/config.
In `@images/ansible-operator/pipfile.Dockerfile`:
- Around line 24-26: Update generate_requirements.py to use pipenv audit instead
of the legacy Safety-based pipenv check flow, and revise its
vulnerability-output parsing to handle pip-audit results consistently with the
Dockerfile’s pipenv audit command; alternatively, document the intentional
divergence if preserving the existing behavior.
In `@openshift/hack/generate_requirements.py`:
- Around line 531-532: Make the intermediate filenames created in the recursive
package-splitting flow unique across sibling groups by replacing the
depth/package-count naming in merged_in and merged_out with a monotonic counter
or tempfile-based allocation within tmp. Also remove the hardcoded _depth=10
workaround and pass or derive the actual recursion depth consistently through
the relevant generation function.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: fd431b66-4748-4cc2-aede-730d023d1992
⛔ Files ignored due to path filters (255)
go.sumis excluded by!**/*.sumimages/ansible-operator/Pipfile.lockis excluded by!**/*.lockopenshift/Pipfile.lockis excluded by!**/*.lockvendor/cel.dev/expr/BUILD.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/MODULE.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/checked.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/eval.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/explain.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/syntax.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/value.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/.gitignoreis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/core_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/command/program.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/main.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/ginkgo.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/outline.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/run/run_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/watch/watch_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo_t_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/helpergo_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/global/init.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/suite.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/testingtproxy/testing_t_proxy.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/reporters/default_reporter.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/config.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/flags.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/version.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/format/format.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/gomega_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_a_slice_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_an_array_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/types/types.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/.golangci.ymlis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/Makefileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/RELEASING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/encoder.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/hash.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/internal/attribute.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/kv.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/type_string.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/value.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/baggage/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/dependencies.Dockerfileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/errorhandler/errorhandler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/handler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/state.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/meter.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/trace_context.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/requirements.txtis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/internal/x/features.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/builtin.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/config.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/container.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/env.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id_readfile.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/os.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/process.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/resource.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/simple_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/tracer.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/provider.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/sampling.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/span.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/attribute_group.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/doc.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/error_type.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/exception.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/otelconv/metric.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/schema.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/auto.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/trace.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/tracestate.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/versions.yamlis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/node.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/nodetype_string.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_conn_pool.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go127.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_random.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/pre_go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/punycode.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpsfv/httpsfv.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/deviceauth.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/oauth2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/pkce.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/token.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/singleflight/singleflight.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/plan9/syscall_plan9.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_signed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_unsigned.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkall.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_solaris.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_unix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/dll_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/registry/key.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/security_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/edge/edge.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/cursor.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/inspector.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/golist.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases_go122.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/core/event.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/keys/keys.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/label/label.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iexport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iimport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/ureader.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gocommand/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/fix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/mod.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/source_modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/directories.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/index.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/lookup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/symbols.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/pkgbits/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/deps.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/coretype.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/free.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/types.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/versions/features.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/balancer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirst.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirstleaf/pickfirstleaf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/roundrobin/roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/subconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/binarylog/grpc_binarylog_v1/binarylog.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/credentials.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/tls.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/encoding.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/gzip/gzip.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/proto/proto.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metricregistry.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metrics.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health_grpc.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/interceptor.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/gracefulswitch/gracefulswitch.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/weight/weight.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/buffer/unbounded.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/channelz/trace.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/envconfig.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/xds.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/experimental.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/idle/idle.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/delegatingresolver/delegatingresolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/dns/dns_resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/metrics_recorder_list.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/stats.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/client_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/controlbuf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/flowcontrol.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/handler_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_client.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/server_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/transport.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_pool.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_slice.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffers.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/preloader.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver/resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/rpc_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_lazy.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/version/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/proto.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (23)
.github/workflows/release.yml.github/workflows/test-ansible.yml.github/workflows/test-sanity.yml.github/workflows/unit.ymlMakefilego.modimages/ansible-operator/Dockerfileimages/ansible-operator/Pipfileimages/ansible-operator/pipfile.Dockerfileinternal/version/version.goopenshift/Dockerfile.requirementsopenshift/hack/generate_requirements.mdopenshift/hack/generate_requirements.pyopenshift/release/ansible/ansible_collections/cloud.common-3.0.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.docker-3.12.1.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.library_inventory_filtering_v1-1.1.5.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/kubernetes.core-3.2.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/operator_sdk.util-0.5.0.info/GALAXY.ymlopenshift/requirements-build.txtopenshift/requirements-build1.txtopenshift/requirements-pre-build.txtopenshift/requirements.txttestdata/memcached-molecule-operator/Makefile
🚧 Files skipped from review as they are similar to previous changes (16)
- testdata/memcached-molecule-operator/Makefile
- Makefile
- openshift/release/ansible/ansible_collections/community.docker-3.12.1.info/GALAXY.yml
- internal/version/version.go
- openshift/requirements-build1.txt
- images/ansible-operator/Pipfile
- openshift/release/ansible/ansible_collections/cloud.common-3.0.0.info/GALAXY.yml
- openshift/release/ansible/ansible_collections/kubernetes.core-3.2.0.info/GALAXY.yml
- openshift/Dockerfile.requirements
- openshift/release/ansible/ansible_collections/community.library_inventory_filtering_v1-1.1.5.info/GALAXY.yml
- openshift/requirements.txt
- .github/workflows/release.yml
- images/ansible-operator/Dockerfile
- openshift/release/ansible/ansible_collections/operator_sdk.util-0.5.0.info/GALAXY.yml
- openshift/requirements-build.txt
- openshift/requirements-pre-build.txt
As I can see, some packages have been updated to the latest minor versions (https://github.com/openshift/ansible-operator-plugins/compare/4798c310f62ce08f1b6d640fc1ea81ba020ed4c1..7e914b77ffd5688128fa1156e5724cbb1cdebe5d) during a force push. Don't you think we may need another ART test build? |
chiragkyal
left a comment
There was a problem hiding this comment.
Looks like there is no upstream commits now, everything is squashed into a single commit. Earlier we used to have all the upstream commits + a final Merge tag commit..Did this script change the behaviour?
xref: https://github.com/openshift/ansible-operator-plugins/pull/69/commits
ya, the verify-requirements failed and i first locally regenerated the requirements from the script, saw that the diff was just minor version bumps, and hence checked it in to have the job passed. |
7e914b7 to
5aa4bf7
Compare
|
@chiragkyal Good catch — you're right, and this was an unintended side effect of the restructuring, not something the automation script changed. Root cause: to reorder the downstream commits during the restructuring, the Fix: reconstructed the merge commit properly — same tree/content, same message, but with both parents restored (the downstream line + the actual upstream Force-pushed — the branch history should now look the way you'd expect (all upstream commits + a real two-parent merge commit). |
9de893d to
23b59d6
Compare
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@openshift/Dockerfile.requirements`:
- Around line 29-31: Update stage1_resolve_runtime and auto_fix_cves so any
unresolved runtime CVE terminates requirements generation and fails the build,
preserving success only when all detected CVEs are fixed. Alternatively, remove
the fail-fast claim from the Dockerfile.requirements documentation and add the
project’s explicit accepted-risk process.
- Line 62: Add a final runtime stage after the existing build stage, copying
only the generated requirement artifacts and required runtime executable while
excluding Rust, Cargo, GCC, and development headers. Configure the export
directory as a writable volume owned by a non-root USER, run the ENTRYPOINT
under that user, and define a HEALTHCHECK for the final image.
- Line 24: Update each pip install command in the Dockerfile, including the
command upgrading pip and the commands at the referenced additional locations,
to use --no-cache-dir or remove /root/.cache/pip in the same layer so no pip
cache remains in the final image.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 43d54939-5da2-4b77-a72f-b4cd49aed5ec
📒 Files selected for processing (1)
openshift/Dockerfile.requirements
|
|
||
| VOLUME /tmp/requirements | ||
| ENTRYPOINT ["cp", "./requirements.txt", "./requirements-build.txt", "./requirements-build1.txt", "./requirements-pre-build.txt", "/tmp/requirements/"] | ||
| ENTRYPOINT ["cp", "./requirements.txt", "./requirements-build.txt", "./requirements-build1.txt", "./requirements-pre-build.txt", "./Pipfile.lock", "/tmp/requirements/"] |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Add a restricted final image stage.
This Dockerfile has one FROM instruction. The exported image therefore retains rust, cargo, gcc, and development headers, and its ENTRYPOINT runs as root. It also has no HEALTHCHECK.
Add a final stage that copies only the generated artifacts and required runtime executable. Set a non-root USER, make the writable export volume available to that user, and define the required health check.
As per path instructions, “Multi-stage builds; no build tools in final image”, “USER non-root; never run as root”, and “HEALTHCHECK defined” apply.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/Dockerfile.requirements` at line 62, Add a final runtime stage
after the existing build stage, copying only the generated requirement artifacts
and required runtime executable while excluding Rust, Cargo, GCC, and
development headers. Configure the export directory as a writable volume owned
by a non-root USER, run the ENTRYPOINT under that user, and define a HEALTHCHECK
for the final image.
Source: Path instructions
Replace the manually maintained ~100-line bash pipeline in openshift/Dockerfile.requirements with a Python script that derives all four requirements files entirely from the Pipfile, with no hardcoded package names. openshift/hack/generate_requirements.py implements six stages: Stage 1 - pipenv install + CVE auto-fix via Safety/pipenv update, then pip freeze to capture all pinned runtime packages. Fails the build (non-zero exit) if a CVE cannot be auto-fixed within the existing Pipfile constraints, rather than only printing a warning that could be missed in a build log. Stage 2 - Iterative pip-compile with dynamic conflict exclusion to produce requirements.txt. Packages that make pip-compile fail due to incompatible declared metadata (e.g. conflicting setuptools version ranges) are detected from the error output, excluded from compilation, and appended manually. RPM-installed packages (cryptography, cffi, pycparser, maturin) are commented out in post-processing. Stage 3 - pip_find_builddeps.py is run once per runtime package so that every package's build-system requirements can be associated with it individually. Stage 4 - Conflict detection and phase splitting. Merging all build-dep constraints is attempted with pip-compile; when it fails the conflicting dependency is identified and packages split into an earlier phase (needing the older version) and a later phase (needing the newer version) using three fallback strategies in order: direct upper-bound heuristic, per-package compilation to detect transitive conflicts, and single-package bisection. N discovered phases are mapped to exactly three build files with a greedy merge that verifies compatibility before absorbing each middle phase into the main build group. Build-isolation exact-version pins (e.g. wheel==0.45.1 declared by ansible-core's pyproject.toml) are discovered automatically from pkg_constraints, injected into requirements-pre-build.txt so cachi2 pre-fetches them, and stripped from later phases so those phases resolve newer CVE-fixed versions. No version numbers are hardcoded. Stage 5 - Safety scans each generated build requirements file for CVEs and attempts to fix them by adding minimum-version constraints and re-running pip-compile. Conflicts that prevent the fix are reported with the name of the blocking constraint. Fails the build if any CVE cannot be auto-fixed. Stage 6 - Verifies that every package pinned in Pipfile.lock is correctly represented in requirements.txt: active, unless it's RPM-installed (commented out) or one of pip-compile's own reserved "unsafe" packages - pip, setuptools, distribute (expected to be entirely absent, since Stage 2 compiles requirements.txt without --allow-unsafe). Fails the build on any discrepancy, guarding against a package silently going missing or miscommented. openshift/hack/generate_requirements.md documents the full algorithm. openshift/Dockerfile.requirements is reduced to installing the toolchain and invoking the script. pip and pip-tools are pinned to a tested-compatible pair (rather than "latest") because pip-tools relies on pip's internal, unstable RequirementCommand API and an unpinned pip can outpace the installed pip-tools release, breaking pip-compile with a TypeError. The generated requirements files and Pipfile.lock (updated by any CVE auto-fixes) are exported to the mounted volume by the ENTRYPOINT. This commit only adds the tooling; it does not regenerate the downstream requirements files themselves (see the follow-up "Update downstream requirements" commit for that, generated after the upstream rebase merge below). Co-authored-by: Cursor <cursoragent@cursor.com>
Ansible Operator Plugins v1.42.3 Merge executed via ./rebase-upstream.sh v1.42.3 upstream main Overwritten conflicts: <NONE> Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Regenerate openshift/Pipfile.lock and openshift/requirements*.txt using openshift/hack/generate_requirements.py (make -f openshift/Makefile generate-requirements) against the rebased images/ansible-operator/Pipfile and Pipfile.lock from the v1.42.3 merge above. This is the single downstream-requirements commit for this rebase, combining what previously landed as two separate regenerations (one run against the pre-rebase Pipfile when the generation script was first introduced, and one run against the post-rebase Pipfile) into one commit reflecting only the final, fully-rebased state. Re-run after CI flagged a re-run gap: cffi, packaging, and vcs-versioning (all build-tool dependencies, not runtime packages) picked up patch releases on PyPI between the original generation and CI running verify-requirements, so requirements-build.txt and requirements-pre-build.txt are refreshed to the currently-resolvable pins. No runtime packages (requirements.txt) or Pipfile.lock changed. Co-authored-by: Cursor <cursoragent@cursor.com>
Fixes GHSA-hrxh-6v49-42gf (xDS RBAC and HTTP/2 transport vulnerabilities), flagged by OSV Scanner via CodeRabbit on PR review. Upstream has an equivalent bump queued as an open, stale Dependabot branch (dependabot/go_modules/google.golang.org/grpc-1.82.1) that hasn't merged. Applying it here directly so the fix isn't blocked on that landing; tagged <drop> because the next upstream rebase's vendor regeneration will naturally subsume this once upstream also picks up the bump. go.sum and vendor/ regenerated via `go get google.golang.org/grpc@v1.82.1 && go mod tidy && go mod vendor`. No source in this repo imports grpc directly (it's a transitive dependency only), and `go build ./...` / `go vet ./...` pass unchanged. Co-authored-by: Cursor <cursoragent@cursor.com>
23b59d6 to
d3151bd
Compare
Description of the change:*
Rebase this repo's main branch with upstream https://github.com/operator-framework/ansible-operator-plugins/releases/tag/v1.42.3 tag.
Changes done:
UPSTREAM: <carry>: automate hermetic build requirements generation) onto the rebase branch first, somake -f openshift/Makefile generate-requirementsuses the new Python-based generator (openshift/hack/generate_requirements.py) against the v1.42.3Pipfile/Pipfile.lockinstead of the old manual bash pipeline inopenshift/Dockerfile.requirements.openshift/hack/rebase_upstream.shto allow reusing a pre-existing<version>-rebase-<branch>branch, so the [WIP] UPSTREAM: <carry>: automate hermetic build requirements generation #79 cherry-pick could be staged before running the rest of the script.openshift/hack/rebase_upstream.sh v1.42.3, which merged upstream tagv1.42.3(no conflicts), rango mod tidy && go mod vendor, regeneratedopenshift/release/ansible/ansible_collections(only benign galaxy metadata URL diffs), and regeneratedopenshift/requirements*.txt/openshift/Pipfile.lockvia the new generator.Motivation for the change:
Pick up upstream v1.42.3, which bumps the Go toolchain to 1.26.3 and updates several Go/Python dependencies for CVE fixes (cryptography, urllib3, idna, requests, grpc, pyasn1, pip/pipenv, ubi9-minimal, etc.), while also landing the automated hermetic build-requirements generation from [WIP] UPSTREAM: <carry>: automate hermetic build requirements generation #79 ahead of the dependency regeneration so the new requirements files are produced by the maintained script rather than the manual bash pipeline.
Summary by CodeRabbit
New Features
Security
Release
Maintenance