Skip to content

feat: add PR-scoped TA Validator exceptions - #539

Merged
mkolasinski-splunk merged 51 commits into
developfrom
codex/pr-scoped-gssa-xfail-workflow
Oct 1, 2026
Merged

mkolasinski-splunk merged 51 commits into
developfrom
codex/pr-scoped-gssa-xfail-workflow

Conversation

@mkolasinski-splunk

@mkolasinski-splunk mkolasinski-splunk commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Implements the reusable-workflow side of PR-scoped TA Validator exceptions.

Permanent and temporary exceptions use the same canonical YAML schema. The workflow extracts only the marked YAML from the automation-managed PR comment; the TA Validator image validates and merges it with the repository's .ta-validator-exceptions.yaml. Evaluation then consumes the single effective file through the normal TA Validator path.

Interface

  • Canonical declarations use check_slug, optional detection_slug, category, and justification.
  • The workflow transports the marked YAML unchanged; TA Validator owns schema, catalog, target, duplicate, and unused-declaration validation.
  • The shared action exposes only image, mode, and AWS authentication inputs.
  • merge reads $RUNNER_TEMP/ta-validator-comment-exceptions.yaml and writes $RUNNER_TEMP/.ta-validator-exceptions.yaml.
  • The effective file is transported as the ta-validator-exceptions artifact.
  • evaluate installs that file at the add-on's conventional .ta-validator-exceptions.yaml path, then runs normal evaluation.
  • Non-PR runs require no exception-specific argument or environment variable.
  • The default image uses the released TA Validator version tag. Third-party actions introduced by this change use exact patch release tags; this repository's remote composite actions use the exact v5.7.0 release tag.

Related implementation

Current revisions and released image

  • Reusable workflow head: f47fcb2c93a86a2d9b37108d9370f10ccb0f71c9
  • Repository composite-action version: v5.7.0 (created by the merge release)
  • TA Validator main revision: 097b8ae279ca7a4508d261eb1162b2c1d1097df5
  • TA Validator release: 1.6.0
  • Image: 956110764581.dkr.ecr.us-west-2.amazonaws.com/ta-automation/gs-scorecard:1.6.0
  • ECR-resolved digest for verification only: sha256:38a0cc43838328a2d159dfdd03b7b924e173b244c3b255a09bf825130b56c949

Current verification

Released-image AWS TA end-to-end validation

  • #1759 — permanent detection-level plus temporary check-wide: run 36831138701, preparation, TA Validator, effective exceptions, report.
  • The caller pinned reusable workflow 11cd0bed817f5f9c746dfd70054ef651e4a583a4 before the reference simplification and did not override gs-image-version. The job log confirms evaluation used release 1.6.0 at digest sha256:38a0cc43838328a2d159dfdd03b7b924e173b244c3b255a09bf825130b56c949, which is the same released image now selected by the plain 1.6.0 default.
  • Preparation succeeded and produced the merged exception artifact. The full TA Validator job succeeded. In the report, lookup-best-practices is xfail; the duplicate-row finding is XFAIL and carries both the permanent and temporary accepted_gap justifications.
  • The overall caller run is red because of unrelated repository checks; the TA Validator preparation and evaluation jobs both passed. The test-only PR is closed again with its branch and workflow evidence preserved.
  • The v5.7.0 self-references cannot be executed before that release tag exists; they become resolvable when this feat: PR merges and semantic-release publishes v5.7.0.

Pre-release five-scenario coverage

These scenarios used reusable workflow b5459166acb91ab541d13c570a70a9e95f4135e7 and pre-release image mr-140-6bc13d80bfa0-amd64@sha256:b5e5bd8375bb2b89e09b8164710a1fe5282cb0c4cebb8ad5678dc1887f7e150f before MR !140 merged.

The three positive TA Validator jobs passed and applied the expected scopes. The two negative scenarios failed during preparation before full evaluation, as intended. All five test PRs are closed.

Review-fix workflow validation

### Description

Fix aggregate test-report jobs when a test matrix produces a single
summary artifact, and pin the AppInspect CLI action to v2.1.1 (ref:
https://splunk.slack.com/archives/C9YHF0HEJ/p1781698303793169).

### Checklist

- [x] `README.md` has been updated or is not required
- [ ] push trigger tests
- [ ] manual release test
- [ ] automated releases test
- [ ] pull request trigger tests
- [ ] schedule trigger tests
- [x] workflow errors/warnings reviewed and addressed

### Testing done

- `git diff --check` passed.
- `actionlint` passed with the repository's unrelated pre-existing
`create-github-app-token` and `vendor-version` diagnostics excluded.
- Shell-level summary discovery check passed for zero, one, and multiple
artifact layouts.
- Isolated PR branch contains only
`.github/workflows/reusable-build-test-release.yml` changes.
- 

https://github.com/splunk/splunk-add-on-for-symantec-endpoint-protection/actions/runs/33163176345
@mkolasinski-splunk
mkolasinski-splunk requested a review from a team as a code owner September 17, 2026 07:27
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T08:54:55.189021Z f47fcb2 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 84f5cf6264

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/actions/collect-gssa-suppressions/index.js Outdated
Comment thread .github/actions/collect-gssa-suppressions/parser.js Outdated
@mkolasinski-splunk
mkolasinski-splunk force-pushed the codex/pr-scoped-gssa-xfail-workflow branch from 84f5cf6 to 3e77213 Compare September 17, 2026 07:51

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 04055f2542

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/reusable-build-test-release.yml Outdated
@mkolasinski-splunk
mkolasinski-splunk force-pushed the codex/pr-scoped-gssa-xfail-workflow branch from bd21624 to 824a474 Compare September 21, 2026 13:36

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 824a474a68

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/actions/prepare-ta-validator-exceptions/prepare.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cd7857318a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md Outdated
Comment thread .github/workflows/reusable-build-test-release.yml Outdated
Comment thread .github/workflows/reusable-build-test-release.yml Outdated
Comment thread README.md Outdated
- `SPL_COM_USER` and `SPL_COM_PASSWORD` for AppInspect integration

- Check that the Docker image version specified via the `gs-image-version` workflow input (`GS_IMAGE_VERSION` env var, default `1.2`) exists in the ECR registry. The GS Scorecard tool version is controlled separately via `gs-version` input (`GS_VERSION` env var, default `0.3`).
- Check that the Docker image version specified via the `gs-image-version` workflow input (`GS_IMAGE_VERSION` env var, default `mr-140-3fee426db3a8-amd64`) exists in the ECR registry. This immutable pre-release image implements the effective-file interface; replace it with the compatible official image after the TA Validator release. The TA Validator tool version is controlled separately via `gs-version` input (`GS_VERSION` env var, default `0.3`).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shouldn't we wait with this PR until MR140 is merged?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, indeed. First TA Validator needs to be released, then this reference needs to be updated.

@rasteja rasteja left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Inline review comments on the exception artifact rerun behavior, workspace symlink handling, and preparation job gating.

Comment thread .github/workflows/reusable-build-test-release.yml
Comment thread .github/actions/run-ta-validator/action.yml Outdated
Comment thread .github/workflows/reusable-build-test-release.yml Outdated
rasteja
rasteja previously approved these changes Sep 30, 2026
@mkolasinski-splunk
mkolasinski-splunk changed the base branch from main to develop October 1, 2026 08:24

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8eca8f091b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/actions/prepare-ta-validator-exceptions/action.yml Outdated

@rasteja rasteja left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Question about the AppInspect action version.

Comment thread .github/workflows/reusable-build-test-release.yml
rasteja
rasteja previously approved these changes Oct 1, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c11338874e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/reusable-build-test-release.yml Outdated
@mkolasinski-splunk
mkolasinski-splunk merged commit e884eeb into develop Oct 1, 2026
9 checks passed
@mkolasinski-splunk
mkolasinski-splunk deleted the codex/pr-scoped-gssa-xfail-workflow branch October 1, 2026 11:14
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants