You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
chore(ci): toolchain key should ignore comment-only .trivyignore edits #1505
The toolchain freshness guard (Toolchain pin freshness (verify-toolchain-pin)) fails when .trivyignore changes in a comment-only way. scripts/toolchain-key.sh hashes .trivyignore byte for byte (input #5), so editing a comment line moves the toolchain key even though the effective ignore set is unchanged. The Dockerfile pin (CHARON_TOOLCHAIN_TAG) then looks stale, and the required check fails.
Evidence
Release PR chore(main): release 0.44.3 #1504 (release-please--branches--main): the check failed with Toolchain recipe/pins changed (recomputed caddy-crowdsec-ee1028e3a9426fa5, Dockerfile pins caddy-crowdsec-04ecbc386f253556).
Commit bdaf4f44 on that branch changed one comment line in .trivyignore (zlib -r0 to -r1 in a comment; the suppressed CVE ID line is untouched) alongside the functional .grype.yaml version bump.
Reproduced locally: scripts/toolchain-key.sh on main returns 04ecbc38… (matches the pin); on the release branch it returns ee1028e3….
toolchain-image.yml rebuilds on .trivyignore changes and opens bump PRs for development, main and nightly. A commit pushed directly to the release-please branch is none of those, so nothing moves the pin there. The guard also cannot tell a comment edit from a real suppression change, so documentation edits force a full toolchain image rebuild.
Severity
Medium (CI friction): blocks required checks on release and PR branches, and forces needless image rebuilds. No security impact.
Suggested approach
In scripts/toolchain-key.sh, hash only the effective .trivyignore entries (strip comment and blank lines, and trailing whitespace) instead of the raw file.
Bump SCHEMA_VERSION (the extraction logic changes), accepting a one-time rebuild of the toolchain image and a pin refresh.
Update scripts/tests/toolchain-key.bats: keep "changes when .trivyignore changes" (add an entry), and add "does not change when only a comment or blank line changes".
Check whether other inputs have the same comment sensitivity (the extracted Dockerfile stage text is intentionally raw; confirm that is still desired).
Land via development as a normal PR, since it changes CI tooling and rebuilds the image.
Immediate unblock for #1504 (separate from this fix)
Either let the pending toolchain image job finish and see whether a bump follows, or revert the comment-only .trivyignore change on the release branch (the functional fix is in .grype.yaml). Note release-please may rewrite its branch on its next run.
Problem
The toolchain freshness guard (
Toolchain pin freshness (verify-toolchain-pin)) fails when.trivyignorechanges in a comment-only way.scripts/toolchain-key.shhashes.trivyignorebyte for byte (input #5), so editing a comment line moves the toolchain key even though the effective ignore set is unchanged. The Dockerfile pin (CHARON_TOOLCHAIN_TAG) then looks stale, and the required check fails.Evidence
release-please--branches--main): the check failed withToolchain recipe/pins changed (recomputed caddy-crowdsec-ee1028e3a9426fa5, Dockerfile pins caddy-crowdsec-04ecbc386f253556).bdaf4f44on that branch changed one comment line in.trivyignore(zlib-r0to-r1in a comment; the suppressed CVE ID line is untouched) alongside the functional.grype.yamlversion bump.scripts/toolchain-key.shonmainreturns04ecbc38…(matches the pin); on the release branch it returnsee1028e3….Why it is not self-healing
toolchain-image.ymlrebuilds on.trivyignorechanges and opens bump PRs fordevelopment,mainandnightly. A commit pushed directly to the release-please branch is none of those, so nothing moves the pin there. The guard also cannot tell a comment edit from a real suppression change, so documentation edits force a full toolchain image rebuild.Severity
Medium (CI friction): blocks required checks on release and PR branches, and forces needless image rebuilds. No security impact.
Suggested approach
scripts/toolchain-key.sh, hash only the effective.trivyignoreentries (strip comment and blank lines, and trailing whitespace) instead of the raw file.SCHEMA_VERSION(the extraction logic changes), accepting a one-time rebuild of the toolchain image and a pin refresh.scripts/tests/toolchain-key.bats: keep "changes when.trivyignorechanges" (add an entry), and add "does not change when only a comment or blank line changes".developmentas a normal PR, since it changes CI tooling and rebuilds the image.Immediate unblock for #1504 (separate from this fix)
Either let the pending toolchain image job finish and see whether a bump follows, or revert the comment-only
.trivyignorechange on the release branch (the functional fix is in.grype.yaml). Note release-please may rewrite its branch on its next run.