Repository navigation
feat: add PR-scoped TA Validator exceptions - #539
Conversation
### Description Fix aggregate test-report jobs when a test matrix produces a single summary artifact, and pin the AppInspect CLI action to v2.1.1 (ref: https://splunk.slack.com/archives/C9YHF0HEJ/p1781698303793169). ### Checklist - [x] `README.md` has been updated or is not required - [ ] push trigger tests - [ ] manual release test - [ ] automated releases test - [ ] pull request trigger tests - [ ] schedule trigger tests - [x] workflow errors/warnings reviewed and addressed ### Testing done - `git diff --check` passed. - `actionlint` passed with the repository's unrelated pre-existing `create-github-app-token` and `vendor-version` diagnostics excluded. - Shell-level summary discovery check passed for zero, one, and multiple artifact layouts. - Isolated PR branch contains only `.github/workflows/reusable-build-test-release.yml` changes. - https://github.com/splunk/splunk-add-on-for-symantec-endpoint-protection/actions/runs/33163176345
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 84f5cf6264
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
84f5cf6 to
3e77213
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 04055f2542
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
bd21624 to
824a474
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 824a474a68
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cd7857318a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - `SPL_COM_USER` and `SPL_COM_PASSWORD` for AppInspect integration | ||
|
|
||
| - Check that the Docker image version specified via the `gs-image-version` workflow input (`GS_IMAGE_VERSION` env var, default `1.2`) exists in the ECR registry. The GS Scorecard tool version is controlled separately via `gs-version` input (`GS_VERSION` env var, default `0.3`). | ||
| - Check that the Docker image version specified via the `gs-image-version` workflow input (`GS_IMAGE_VERSION` env var, default `mr-140-3fee426db3a8-amd64`) exists in the ECR registry. This immutable pre-release image implements the effective-file interface; replace it with the compatible official image after the TA Validator release. The TA Validator tool version is controlled separately via `gs-version` input (`GS_VERSION` env var, default `0.3`). |
There was a problem hiding this comment.
Shouldn't we wait with this PR until MR140 is merged?
There was a problem hiding this comment.
Yes, indeed. First TA Validator needs to be released, then this reference needs to be updated.
rasteja
left a comment
There was a problem hiding this comment.
Inline review comments on the exception artifact rerun behavior, workspace symlink handling, and preparation job gating.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8eca8f091b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
rasteja
left a comment
There was a problem hiding this comment.
Question about the AppInspect action version.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c11338874e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Implements the reusable-workflow side of PR-scoped TA Validator exceptions.
Permanent and temporary exceptions use the same canonical YAML schema. The workflow extracts only the marked YAML from the automation-managed PR comment; the TA Validator image validates and merges it with the repository's
.ta-validator-exceptions.yaml. Evaluation then consumes the single effective file through the normal TA Validator path.Interface
check_slug, optionaldetection_slug,category, andjustification.image,mode, and AWS authentication inputs.mergereads$RUNNER_TEMP/ta-validator-comment-exceptions.yamland writes$RUNNER_TEMP/.ta-validator-exceptions.yaml.ta-validator-exceptionsartifact.evaluateinstalls that file at the add-on's conventional.ta-validator-exceptions.yamlpath, then runs normal evaluation.v5.7.0release tag.Related implementation
Current revisions and released image
f47fcb2c93a86a2d9b37108d9370f10ccb0f71c9v5.7.0(created by the merge release)097b8ae279ca7a4508d261eb1162b2c1d1097df51.6.0956110764581.dkr.ecr.us-west-2.amazonaws.com/ta-automation/gs-scorecard:1.6.0sha256:38a0cc43838328a2d159dfdd03b7b924e173b244c3b255a09bf825130b56c949Current verification
pre_commit,unit_tests,release, andbuild_and_push_integration_docker_imagepassed. The release job published1.6.0; ECR independently resolves that tag to the digest above.f47fcb2c93a86a2d9b37108d9370f10ccb0f71c9; publishing was skipped as expected for a pull request.Released-image AWS TA end-to-end validation
11cd0bed817f5f9c746dfd70054ef651e4a583a4before the reference simplification and did not overridegs-image-version. The job log confirms evaluation used release1.6.0at digestsha256:38a0cc43838328a2d159dfdd03b7b924e173b244c3b255a09bf825130b56c949, which is the same released image now selected by the plain1.6.0default.lookup-best-practicesisxfail; the duplicate-row finding isXFAILand carries both the permanent and temporaryaccepted_gapjustifications.v5.7.0self-references cannot be executed before that release tag exists; they become resolvable when thisfeat:PR merges and semantic-release publishesv5.7.0.Pre-release five-scenario coverage
These scenarios used reusable workflow
b5459166acb91ab541d13c570a70a9e95f4135e7and pre-release imagemr-140-6bc13d80bfa0-amd64@sha256:b5e5bd8375bb2b89e09b8164710a1fe5282cb0c4cebb8ad5678dc1887f7e150fbefore MR !140 merged.The three positive TA Validator jobs passed and applied the expected scopes. The two negative scenarios failed during preparation before full evaluation, as intended. All five test PRs are closed.
Review-fix workflow validation
setup-workflowpassed andprepare-ta-validator-exceptionswas skipped, verifying the disabled-validator path.