Merge pull request 'Stabilize the protected production release' (#8) from codex/stabilize-ai-sbom into main
GeoIntel release gates / Compile, test, contracts and builds (push) Successful in 2m11s
GeoIntel release gates / Python and npm vulnerability policy (push) Successful in 21s
GeoIntel release gates / Production AI image, SBOM and container scan (push) Successful in 5m38s
GeoIntel release gates / Deploy exact gated revision to Unraid (push) Failing after 52m59s
GeoIntel release gates / Compile, test, contracts and builds (push) Successful in 2m11s
GeoIntel release gates / Python and npm vulnerability policy (push) Successful in 21s
GeoIntel release gates / Production AI image, SBOM and container scan (push) Successful in 5m38s
GeoIntel release gates / Deploy exact gated revision to Unraid (push) Failing after 52m59s
This commit was merged in pull request #8.
This commit is contained in:
@@ -123,6 +123,8 @@ def test_scanner_images_are_versioned_and_digest_pinned() -> None:
|
||||
assert 'docker save "$IMAGE_ID"' in sbom
|
||||
assert '"docker-archive:$WORKDIR/$IMAGE_ARCHIVE"' in sbom
|
||||
assert 'SYFT_PARALLELISM=${SYFT_PARALLELISM:-1}' in sbom
|
||||
assert 'GOMEMLIMIT=${SYFT_GOMEMLIMIT:-4GiB}' in sbom
|
||||
assert 'GOGC=${SYFT_GOGC:-25}' in sbom
|
||||
assert "--select-catalogers=-binary" in sbom
|
||||
assert '--volumes-from "$HOSTNAME"' in sbom
|
||||
assert 'ARCHIVE_ID_FILE="${IMAGE_ARCHIVE}.image-id"' in sbom
|
||||
|
||||
@@ -45,6 +45,8 @@ def test_backup_binds_prepared_source_without_requiring_dot_git() -> None:
|
||||
optional_git_fallback = script.index('if command -v git >/dev/null 2>&1')
|
||||
docker_access = script.index("docker inspect -f '{{.State.Running}}'")
|
||||
assert controller_resolution < optional_git_fallback < docker_access
|
||||
assert 'git -C "$ROOT" rev-parse --show-toplevel' in script
|
||||
assert '"$(cd "$git_top" && pwd -P)" = "$(cd "$ROOT" && pwd -P)"' in script
|
||||
assert 'SOURCE_REVISION="$explicit_sha"' in script
|
||||
assert '"backup_tool_revision": ${SOURCE_REVISION@Q}' in script
|
||||
assert '"running_image_revision": ${RUNNING_IMAGE_REVISION@Q}' in script
|
||||
|
||||
@@ -70,7 +70,7 @@ done
|
||||
resolve_source_revision() {
|
||||
local controller_sha="" explicit_sha="${GEOINTEL_BUILD_SHA:-}"
|
||||
local gitea_sha="${GITEA_COMMIT_SHA:-}" github_sha="${GITHUB_SHA:-}"
|
||||
local git_head="" git_dirty="false" source=""
|
||||
local git_head="" git_top="" git_dirty="false" source=""
|
||||
|
||||
if [ -n "$gitea_sha" ]; then
|
||||
if ! [[ "$gitea_sha" =~ ^[0-9A-Fa-f]{40}$ ]]; then
|
||||
@@ -115,6 +115,9 @@ resolve_source_revision() {
|
||||
fi
|
||||
|
||||
if command -v git >/dev/null 2>&1 && git -C "$ROOT" rev-parse --git-dir >/dev/null 2>&1; then
|
||||
git_top="$(git -C "$ROOT" rev-parse --show-toplevel 2>/dev/null || true)"
|
||||
fi
|
||||
if [ -n "$git_top" ] && [ "$(cd "$git_top" && pwd -P)" = "$(cd "$ROOT" && pwd -P)" ]; then
|
||||
git_head="$(git -C "$ROOT" rev-parse HEAD 2>/dev/null || true)"
|
||||
git_head="${git_head,,}"
|
||||
if ! [[ "$git_head" =~ ^[0-9a-f]{40}$ ]]; then
|
||||
|
||||
@@ -57,13 +57,16 @@ if [[ -n "${HOSTNAME:-}" ]] && docker inspect --type container "$HOSTNAME" >/dev
|
||||
WORKSPACE_ARGS=(--volumes-from "$HOSTNAME")
|
||||
fi
|
||||
|
||||
# CUDA and PyTorch ship several gigabytes of native binaries. Syft's heuristic
|
||||
# binary catalogers exceed the isolated runner's 8 GiB limit on that content.
|
||||
# Authoritative dpkg, Python, npm and other installed-package catalogers remain
|
||||
# enabled; Trivy still scans the complete immutable archive independently.
|
||||
# CUDA and PyTorch ship several gigabytes of native binaries. Keep Syft's Go
|
||||
# heap below the isolated runner's 8 GiB limit and collect garbage proactively;
|
||||
# otherwise the Docker-in-Docker job can be OOM-killed even with one cataloger
|
||||
# worker. Authoritative dpkg, Python, npm and other installed-package catalogers
|
||||
# remain enabled; Trivy still scans the complete immutable archive independently.
|
||||
docker run --rm \
|
||||
--user 0:0 \
|
||||
-e "SYFT_PARALLELISM=${SYFT_PARALLELISM:-1}" \
|
||||
-e "GOMEMLIMIT=${SYFT_GOMEMLIMIT:-4GiB}" \
|
||||
-e "GOGC=${SYFT_GOGC:-25}" \
|
||||
"${WORKSPACE_ARGS[@]}" \
|
||||
-w "$WORKDIR" \
|
||||
"$SYFT_IMAGE" \
|
||||
|
||||
Reference in New Issue
Block a user