OAPE-836: V1.42.3 Rebase openshift/main with upstream v1.42.3#82
OAPE-836: V1.42.3 Rebase openshift/main with upstream v1.42.3#82mytreya-rh wants to merge 22 commits into
Conversation
Bumps [pyasn1](https://github.com/pyasn1/pyasn1) from 0.6.2 to 0.6.3. - [Release notes](https://github.com/pyasn1/pyasn1/releases) - [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst) - [Commits](pyasn1/pyasn1@v0.6.2...v0.6.3) --- updated-dependencies: - dependency-name: pyasn1 dependency-version: 0.6.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.75.1 to 1.79.3. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.75.1...v1.79.3) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.79.3 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0. - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.5...v2.33.0) --- updated-dependencies: - dependency-name: requests dependency-version: 2.33.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#215) Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.5 to 46.0.6. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.5...46.0.6) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.40.0 to 1.43.0. - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.40.0...v1.43.0) --- updated-dependencies: - dependency-name: go.opentelemetry.io/otel/sdk dependency-version: 1.43.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#217) Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.6 to 46.0.7. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.6.3...2.7.0) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.7.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [idna](https://github.com/kjd/idna) from 3.11 to 3.15. - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md) - [Commits](kjd/idna@v3.11...v3.15) --- updated-dependencies: - dependency-name: idna dependency-version: '3.15' dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#225) Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.7 to 48.0.1. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...48.0.1) --- updated-dependencies: - dependency-name: cryptography dependency-version: 48.0.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
…e to reduce cve footprint (#227) Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps ubi9/ubi-minimal from 9.7 to 9.8. --- updated-dependencies: - dependency-name: ubi9/ubi-minimal dependency-version: '9.8' dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Update go.mod need 1.26.1. version to fix CVE-2026-25679,CVE-2026-27139,CVE-2026-27142 Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> * Update go.mod Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> * Update go.mod Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> --------- Signed-off-by: Preethi-Ps <nannetpreethi@gmail.com> Co-authored-by: Preethi-Ps <nannetpreethi@gmail.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Replace the manually maintained ~100-line bash pipeline in openshift/Dockerfile.requirements with a Python script that derives all four requirements files entirely from the Pipfile, with no hardcoded package names. openshift/hack/generate_requirements.py implements five stages: Stage 1 – pipenv install + CVE auto-fix via Safety/pipenv update, then pip freeze to capture all pinned runtime packages. Stage 2 – Iterative pip-compile with dynamic conflict exclusion to produce requirements.txt. Packages that make pip-compile fail due to incompatible declared metadata (e.g. conflicting setuptools version ranges) are detected from the error output, excluded from compilation, and appended manually. RPM-installed packages (cryptography, cffi, pycparser, maturin) are commented out in post-processing. Stage 3 – pip_find_builddeps.py is run once per runtime package so that every package's build-system requirements can be associated with it individually. Stage 4 – Conflict detection and phase splitting. Merging all build-dep constraints is attempted with pip-compile; when it fails the conflicting dependency is identified and packages split into an earlier phase (needing the older version) and a later phase (needing the newer version) using three fallback strategies in order: direct upper-bound heuristic, per-package compilation to detect transitive conflicts, and single-package bisection. N discovered phases are mapped to exactly three build files with a greedy merge that verifies compatibility before absorbing each middle phase into the main build group. Build-isolation exact-version pins (e.g. wheel==0.45.1 declared by ansible-core's pyproject.toml) are discovered automatically from pkg_constraints, injected into requirements-pre-build.txt so cachi2 pre-fetches them, and stripped from later phases so those phases resolve newer CVE-fixed versions. No version numbers are hardcoded. Stage 5 – Safety scans each generated build requirements file for CVEs and attempts to fix them by adding minimum-version constraints and re-running pip-compile. Conflicts that prevent the fix are reported with the name of the blocking constraint. openshift/hack/generate_requirements.md documents the full algorithm. openshift/Dockerfile.requirements is reduced to installing the toolchain and invoking the script. The generated requirements files and Pipfile.lock (updated by any CVE auto-fixes) are exported to the mounted volume by the ENTRYPOINT. The regenerated requirements files reflect: - pyasn1 0.6.2 → 0.6.3 (CVE-2026-30922) - requests 2.32.5 → 2.33.1 (CVE-2026-25645) - wheel 0.46.3 → 0.47.0 in requirements-build.txt (CVE-2026-24049; 0.45.1 is retained in requirements-pre-build.txt for ansible-core build isolation as discovered from its build-system metadata) - certifi, charset-normalizer, idna, packaging, pathspec, poetry-core, setuptools, trove-classifiers bumped to latest - kubernetes 33.1.0 build deps skipped (internal setuptools-scm conflict in the package's own build-system declaration) Co-authored-by: Cursor <cursoragent@cursor.com>
…ebase branch Supports pre-creating the <version>-rebase-<branch> branch and staging commits on it (e.g. cherry-picks) before running the script. Co-authored-by: Cursor <cursoragent@cursor.com>
Ansible Operator Plugins v1.42.3 Merge executed via ./rebase-upstream.sh v1.42.3 upstream main Overwritten conflicts: <NONE> Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
|
@mytreya-rh: This pull request references OAPE-836 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mytreya-rh The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
WalkthroughThe change adds a five-stage OpenShift requirements generator and wires it into the Docker build. It also refreshes generated dependency files, Go and Python tooling, release versions, GitHub Actions checkout versions, Galaxy URLs, and rebase branch handling. ChangesHermetic requirements generation
Release and build maintenance
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant Dockerfile.requirements
participant generate_requirements.py
participant pipenv
participant pip_compile
participant pip_find_builddeps
Dockerfile.requirements->>generate_requirements.py: invoke generator
generate_requirements.py->>pipenv: resolve and freeze runtime dependencies
generate_requirements.py->>pip_compile: compile runtime and build requirements
generate_requirements.py->>pip_find_builddeps: collect build constraints
generate_requirements.py-->>Dockerfile.requirements: write requirements files and Pipfile.lock
Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (2 errors)
✅ Passed checks (13 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 14
🧹 Nitpick comments (5)
images/ansible-operator/Pipfile (1)
8-11: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winPin the build-tool installs exactly
pip~=26.1.2and the unpinnedpip-auditin both Dockerfiles can drift; use exact versions there. ThePipfileentries already resolve to exact versions throughPipfile.lock, so they don’t need==pins.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@images/ansible-operator/Pipfile` around lines 8 - 11, Pin the build-tool dependencies exactly in both Dockerfiles: update pip to 26.1.2 and assign an exact version to pip-audit in images/ansible-operator/Dockerfile lines 29-30 and images/ansible-operator/pipfile.Dockerfile lines 23-24. No change is required in images/ansible-operator/Pipfile lines 8-11 because its lockfile already resolves those entries exactly.Source: Path instructions
openshift/hack/generate_requirements.py (3)
452-468: 🎯 Functional Correctness | 🔵 Trivial | 💤 Low valueGap heuristic splits on patch-only differences.
When every consecutive gap is
0(e.g. resolved versions8.1.0and8.1.2),max_gapnever exceeds0,split_afterstays atunique[0], and the group is split even though no major/minor conflict exists. The recursion re-validates each sub-group, so the result is only extra phases rather than a wrong one — but requiringmax_gap > 0before splitting would avoid the spurious phase.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 452 - 468, Update the gap-splitting logic around split_after and max_gap so it returns no split when the largest major/minor gap is zero, including patch-only differences. Only compute and return the older group when max_gap is greater than zero; preserve the existing split behavior for genuine major/minor gaps.
203-207: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win
_min_safe_versionpicks the last upper bound, not the tightest.For multi-clause specs (Safety often emits ranges joined by
||, e.g.<1.9 || >=2.0,<2.1), the last<Xmatch is the newest bound, so the inferred "min safe version" can silently overshoot or undershoot. Selecting the maximum bound withpackaging.version.Versionmakes the intent explicit and matches the docstring.♻️ Proposed refactor
- # Find the tightest upper bound: the version just after <X - best: str | None = None - for m in re.finditer(r"<([0-9][0-9a-zA-Z._-]*)", affected_spec): - best = m.group(1) # last match wins (most restrictive) - return best + # Pick the highest upper bound across all clauses so the resulting + # ">=best" constraint clears every affected range. + from packaging.version import InvalidVersion, Version + + best: str | None = None + for m in re.finditer(r"<([0-9][0-9a-zA-Z._-]*)", affected_spec): + cand = m.group(1) + if best is None: + best = cand + continue + try: + if Version(cand) > Version(best): + best = cand + except InvalidVersion: + best = cand + return best🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 203 - 207, Update _min_safe_version to compare every matched upper-bound version using packaging.version.Version and retain the maximum bound rather than relying on the last regex match. Return the selected version in the existing string format, preserving None when no upper bounds are found.
625-629: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueEvery committed lockfile header now records absolute
/requirements*.inpaths.stage2_runtime_txtwrites the compile input intoout_dirspecifically to keep pip-compile's# viaannotations relative-looking, but the container invokes the generator with the default--output-dir .at/, so all three regenerated files carry/requirements-*.inannotations instead of the previous relative form. Harmless for pip, but it inflates the diff on every regeneration.
openshift/hack/generate_requirements.py#L625-L629: either write the.infiles relative to the process CWD, or update the comment to reflect that the annotation path follows--output-dir.openshift/requirements-build.txt#L5-L6: regenerate once the output directory is a real subdirectory so annotations return to the relative form.openshift/requirements-pre-build.txt#L5-L6: same regeneration applies to this header and its# vialines.openshift/requirements.txt#L5-L6: same regeneration applies to this header and its# vialines.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.py` around lines 625 - 629, The stage2_runtime_txt path setup around compile_in and out_txt currently produces absolute # via annotations when --output-dir is /. Make the compile input path relative to the process CWD (or update the comment to accurately document --output-dir-dependent behavior), then regenerate openshift/requirements-build.txt:5-6, openshift/requirements-pre-build.txt:5-6, and openshift/requirements.txt:5-6 using a real subdirectory so their headers and # via lines use relative paths.openshift/hack/generate_requirements.md (1)
27-32: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueAdd languages to fenced code blocks (markdownlint MD040).
Seven fenced blocks (Lines 27, 60, 121, 183, 216, 242, 288) have no language specified.
textis fine for the ASCII diagrams.Also applies to: 60-80, 121-125
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@openshift/hack/generate_requirements.md` around lines 27 - 32, Add the `text` language identifier to the seven unlabeled fenced code blocks in generate_requirements.md, including the blocks around the listed sections, while preserving their existing diagram and content text.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Line 28: Pin every actions/checkout invocation to a full immutable commit SHA
instead of the mutable `@v7` tag: update .github/workflows/release.yml at lines
28-28 and 66-66, .github/workflows/test-ansible.yml at lines 10-10 and 23-23,
.github/workflows/test-sanity.yml at line 10, and .github/workflows/unit.yml at
line 10.
In @.github/workflows/test-ansible.yml:
- Around line 10-12: Add persist-credentials: false to every actions/checkout
step in .github/workflows/test-ansible.yml at lines 10-12 and 23-25,
.github/workflows/test-sanity.yml at lines 10-12, and .github/workflows/unit.yml
at lines 10-12; no other workflow behavior needs changing.
In `@go.mod`:
- Line 110: Update the google.golang.org/grpc dependency in go.mod from v1.79.3
to v1.82.1 or later, and synchronize related module checksums or dependency
metadata so the module build list no longer includes the vulnerable version.
In `@images/ansible-operator/pipfile.Dockerfile`:
- Line 1: Add a non-root user in the basebuilder image, grant that user write
access to /tmp/pip-airlock, and configure the image to run as that user so the
ENTRYPOINT cp operation does not create root-owned Pipfile.lock files.
In `@openshift/Dockerfile.requirements`:
- Around line 33-34: Update the documentation describing hardcoded package
assumptions: in openshift/Dockerfile.requirements lines 33-34, replace the
cachi2-specific wheel pin statement with a note that build-isolation pins are
auto-discovered from package metadata; in
openshift/hack/generate_requirements.py lines 5-7, remove “and cachi2-specific
pins” from the module docstring while leaving the script behavior unchanged.
In `@openshift/hack/generate_requirements.md`:
- Line 188: Update the step-count descriptions in the requirements-generation
documentation: change “five strategies” to “six strategies” near the
recursion-level list and “three-step process” to “four-step process” near the
later numbered list, without changing the steps themselves.
In `@openshift/hack/generate_requirements.py`:
- Around line 882-883: Remove the unnecessary f-string prefixes from the literal
string fragments in the requirement-generation output, including the fragments
near the auto-detected build-isolation pins and the corresponding locations
around lines 1001 and 1236. Preserve the existing concatenation and
interpolation for strings that still contain placeholders.
- Around line 230-239: Update the vulnerability parsing at this path and the
re-check around the second parse site to use the combined check.stdout and
check.stderr streams, matching Stage 5’s _strip_ansi handling. Preserve the
existing warning and auto-fix behavior while ensuring reports emitted on stderr
are parsed and processed.
- Around line 992-999: Change the deferred-package handling around the mapped
phase loop so `later_pkgs` constraints are accumulated when
`requirements-build.in` is not yet available, instead of being dropped. After
the loop has produced the build requirements, append all deferred specs and run
the same `_pip_compile`, `_normalize_quirks`, and `_comment_out` post-processing
used for the normal build output, ensuring RPM-installed packages remain
commented out.
- Around line 1062-1078: Update the Safety invocation loop around safety_cmd so
missing executables are caught as FileNotFoundError and the next command form is
attempted. Remove the premature stderr-based break and only stop when the
command executes successfully or produces a non-missing-command result, while
preserving the existing return-code handling and artifact generation flow.
In `@openshift/hack/rebase_upstream.sh`:
- Around line 49-52: Update the existing-branch path in the rebase_work_branch
reuse logic to ensure the checked-out branch contains the refreshed
rebase_branch before continuing. Merge the updated base into the reused branch,
or perform an ancestry check and abort with a clear message when it is not based
on the refreshed target.
- Around line 50-54: Update the existing-branch path around rebase_work_branch
so git checkout failure aborts the script immediately, matching the failure
handling in the branch-creation path. Preserve the current success behavior and
ensure no merge or commit proceeds when checkout fails.
In `@openshift/requirements-build.txt`:
- Around line 56-74: Update the pinned setuptools version in the requirements
file from 82.0.1 to a patched release that addresses the published advisory,
keeping the existing unsafe-package entry and formatting intact.
In `@openshift/requirements.txt`:
- Around line 33-36: Update the pinned runtime dependency set in
requirements.txt by restoring the rsa package required by google-auth==2.55.0,
using the compatible rsa>=3.1.4,<5 constraint and retaining the existing
generated dependency annotations for the google-auth dependency chain.
---
Nitpick comments:
In `@images/ansible-operator/Pipfile`:
- Around line 8-11: Pin the build-tool dependencies exactly in both Dockerfiles:
update pip to 26.1.2 and assign an exact version to pip-audit in
images/ansible-operator/Dockerfile lines 29-30 and
images/ansible-operator/pipfile.Dockerfile lines 23-24. No change is required in
images/ansible-operator/Pipfile lines 8-11 because its lockfile already resolves
those entries exactly.
In `@openshift/hack/generate_requirements.md`:
- Around line 27-32: Add the `text` language identifier to the seven unlabeled
fenced code blocks in generate_requirements.md, including the blocks around the
listed sections, while preserving their existing diagram and content text.
In `@openshift/hack/generate_requirements.py`:
- Around line 452-468: Update the gap-splitting logic around split_after and
max_gap so it returns no split when the largest major/minor gap is zero,
including patch-only differences. Only compute and return the older group when
max_gap is greater than zero; preserve the existing split behavior for genuine
major/minor gaps.
- Around line 203-207: Update _min_safe_version to compare every matched
upper-bound version using packaging.version.Version and retain the maximum bound
rather than relying on the last regex match. Return the selected version in the
existing string format, preserving None when no upper bounds are found.
- Around line 625-629: The stage2_runtime_txt path setup around compile_in and
out_txt currently produces absolute # via annotations when --output-dir is /.
Make the compile input path relative to the process CWD (or update the comment
to accurately document --output-dir-dependent behavior), then regenerate
openshift/requirements-build.txt:5-6, openshift/requirements-pre-build.txt:5-6,
and openshift/requirements.txt:5-6 using a real subdirectory so their headers
and # via lines use relative paths.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 29944b7a-ce45-4d4b-a48f-d75ab87228fb
⛔ Files ignored due to path filters (255)
go.sumis excluded by!**/*.sumimages/ansible-operator/Pipfile.lockis excluded by!**/*.lockopenshift/Pipfile.lockis excluded by!**/*.lockvendor/cel.dev/expr/BUILD.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/MODULE.bazelis excluded by!**/vendor/**,!vendor/**vendor/cel.dev/expr/checked.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/eval.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/explain.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/syntax.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/cel.dev/expr/value.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/.gitignoreis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/core_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/command/program.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/main.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/ginkgo.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/outline/outline.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/run/run_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo/watch/watch_command.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/ginkgo_t_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/helpergo_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/global/init.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/suite.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/internal/testingtproxy/testing_t_proxy.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/reporters/default_reporter.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/config.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/errors.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/flags.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/ginkgo/v2/types/version.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/README.mdis excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/format/format.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/gomega_dsl.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_a_slice_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/matchers/be_an_array_matcher.gois excluded by!**/vendor/**,!vendor/**vendor/github.com/onsi/gomega/types/types.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/.golangci.ymlis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CHANGELOG.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/Makefileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/RELEASING.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/encoder.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/hash.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/internal/attribute.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/kv.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/type_string.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/attribute/value.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/baggage/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/dependencies.Dockerfileis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/errorhandler/errorhandler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/handler.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/internal/global/state.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/asyncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/meter.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncfloat64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/metric/syncint64.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/baggage.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/propagation/trace_context.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/requirements.txtis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/internal/x/features.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/builtin.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/config.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/container.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/env.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/host_id_readfile.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/os.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/process.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/resource/resource.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/batch_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/simple_span_processor.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/internal/observ/tracer.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/provider.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/sampling.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/trace/span.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/sdk/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.39.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/MIGRATION.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/README.mdis excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/attribute_group.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/doc.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/error_type.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/exception.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/otelconv/metric.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/semconv/v1.40.0/schema.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/auto.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/trace.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/trace/tracestate.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/version.gois excluded by!**/vendor/**,!vendor/**vendor/go.opentelemetry.io/otel/versions.yamlis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/node.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/html/nodetype_string.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/README.mdis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_conn_pool.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go126.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/client_priority_go127.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/config.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/http2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/server_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/transport_wrap.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_common.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_random.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/http2/writesched_roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/idna9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/pre_go118.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/punycode.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables10.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables11.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables15.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables17.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/tables9.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie12.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/idna/trie13.0.0.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpcommon/request.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/net/internal/httpsfv/httpsfv.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/deviceauth.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/oauth2.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/pkce.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/token.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/oauth2/transport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sync/singleflight/singleflight.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/plan9/syscall_plan9.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/affinity_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_signed.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ioctl_unsigned.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/mkall.shis excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_arm64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_loong64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_linux_riscv64.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_solaris.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/syscall_unix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/dll_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/registry/key.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/security_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/edge/edge.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/cursor.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/inspector.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/ast/inspector/iter.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/golist.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/packages/packages.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/go/types/objectpath/objectpath.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/aliases/aliases_go122.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/core/event.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/keys/keys.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/event/label/label.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iexport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/iimport.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gcimporter/ureader.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/gocommand/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/fix.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/mod.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/imports/source_modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/directories.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/index.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/lookup.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/modindex.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/modindex/symbols.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/pkgbits/version.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/stdlib/deps.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/coretype.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typeparams/free.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/typesinternal/types.gois excluded by!**/vendor/**,!vendor/**vendor/golang.org/x/tools/internal/versions/features.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/CONTRIBUTING.mdis excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/balancer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirst.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/pickfirst/pickfirstleaf/pickfirstleaf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/roundrobin/roundrobin.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer/subconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/balancer_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/binarylog/grpc_binarylog_v1/binarylog.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/clientconn.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/credentials.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/credentials/tls.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/encoding.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/gzip/gzip.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/encoding/proto/proto.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metricregistry.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/experimental/stats/metrics.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/health/grpc_health_v1/health_grpc.pb.gois excluded by!**/*.pb.go,!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/interceptor.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/gracefulswitch/gracefulswitch.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/balancer/weight/weight.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/buffer/unbounded.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/channelz/trace.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/envconfig.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/envconfig/xds.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/experimental.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/idle/idle.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/internal.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/delegatingresolver/delegatingresolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/resolver/dns/dns_resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/metrics_recorder_list.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/stats/stats.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/client_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/controlbuf.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/flowcontrol.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/handler_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_client.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http2_server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/http_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/server_stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/internal/transport/transport.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_pool.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffer_slice.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/mem/buffers.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/preloader.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver/resolver.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/resolver_wrapper.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/rpc_util.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/server.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/stream.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/grpc/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/filedesc/desc_lazy.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/internal/version/version.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/desc_init.gois excluded by!**/vendor/**,!vendor/**vendor/google.golang.org/protobuf/reflect/protodesc/proto.gois excluded by!**/vendor/**,!vendor/**vendor/modules.txtis excluded by!**/vendor/**,!vendor/**
📒 Files selected for processing (24)
.github/workflows/release.yml.github/workflows/test-ansible.yml.github/workflows/test-sanity.yml.github/workflows/unit.ymlMakefilego.modimages/ansible-operator/Dockerfileimages/ansible-operator/Pipfileimages/ansible-operator/pipfile.Dockerfileinternal/version/version.goopenshift/Dockerfile.requirementsopenshift/hack/generate_requirements.mdopenshift/hack/generate_requirements.pyopenshift/hack/rebase_upstream.shopenshift/release/ansible/ansible_collections/cloud.common-3.0.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.docker-3.12.1.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/community.library_inventory_filtering_v1-1.1.5.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/kubernetes.core-3.2.0.info/GALAXY.ymlopenshift/release/ansible/ansible_collections/operator_sdk.util-0.5.0.info/GALAXY.ymlopenshift/requirements-build.txtopenshift/requirements-build1.txtopenshift/requirements-pre-build.txtopenshift/requirements.txttestdata/memcached-molecule-operator/Makefile
| steps: | ||
| - name: Check out code into the Go module directory | ||
| uses: actions/checkout@v6 | ||
| uses: actions/checkout@v7 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf 'Occurrences of actions/checkout in workflow files:\n'
rg -n "actions/checkout@" .github/workflows
printf '\nRelevant file excerpts:\n'
for f in .github/workflows/release.yml .github/workflows/test-ansible.yml .github/workflows/test-sanity.yml .github/workflows/unit.yml; do
echo "==== $f ===="
nl -ba "$f" | sed -n '1,120p'
echo
doneRepository: openshift/ansible-operator-plugins
Length of output: 736
Pin actions/checkout to full commit SHAs. @v7 is a mutable tag and leaves the workflow supply chain unpinned.
.github/workflows/release.yml(lines 28, 66).github/workflows/test-ansible.yml(lines 10, 23).github/workflows/test-sanity.yml(line 10).github/workflows/unit.yml(line 10)
📍 Affects 4 files
.github/workflows/release.yml#L28-L28(this comment).github/workflows/release.yml#L66-L66.github/workflows/test-ansible.yml#L10-L10.github/workflows/test-ansible.yml#L23-L23.github/workflows/test-sanity.yml#L10-L10.github/workflows/unit.yml#L10-L10
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/release.yml at line 28, Pin every actions/checkout
invocation to a full immutable commit SHA instead of the mutable `@v7` tag: update
.github/workflows/release.yml at lines 28-28 and 66-66,
.github/workflows/test-ansible.yml at lines 10-10 and 23-23,
.github/workflows/test-sanity.yml at line 10, and .github/workflows/unit.yml at
line 10.
Source: Path instructions
| - uses: actions/checkout@v7 | ||
| with: | ||
| fetch-depth: 0 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== Workflow files ==\n'
git ls-files .github/workflows/*.yml .github/workflows/*.yaml
printf '\n== Relevant checkout steps ==\n'
for f in .github/workflows/test-ansible.yml .github/workflows/test-sanity.yml .github/workflows/unit.yml; do
echo "--- $f ---"
nl -ba "$f" | sed -n '1,220p' | rg -n 'checkout|persist-credentials|fetch-depth|uses: actions/checkout'
doneRepository: openshift/ansible-operator-plugins
Length of output: 431
🏁 Script executed:
#!/bin/bash
set -euo pipefail
for f in .github/workflows/test-ansible.yml .github/workflows/test-sanity.yml .github/workflows/unit.yml; do
echo "--- $f ---"
awk 'NR>=1 && NR<=220 { printf "%4d %s\n", NR, $0 }' "$f" | sed -n '/actions\/checkout/,+6p'
doneRepository: openshift/ansible-operator-plugins
Length of output: 1217
🏁 Script executed:
#!/bin/bash
set -euo pipefail
for f in .github/workflows/test-ansible.yml .github/workflows/test-sanity.yml .github/workflows/unit.yml; do
echo "--- $f ---"
awk 'NR>=1 && NR<=120 { printf "%4d %s\n", NR, $0 }' "$f" | sed -n '1,80p'
doneRepository: openshift/ansible-operator-plugins
Length of output: 2284
Disable persisted checkout credentials in these test jobs.
Add persist-credentials: false to each actions/checkout step in .github/workflows/test-ansible.yml (both jobs), .github/workflows/test-sanity.yml, and .github/workflows/unit.yml; they only run tests after checkout, so keeping GITHUB_TOKEN in .git/config is unnecessary exposure.
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 10-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
📍 Affects 3 files
.github/workflows/test-ansible.yml#L10-L12(this comment).github/workflows/test-ansible.yml#L23-L25.github/workflows/test-sanity.yml#L10-L12.github/workflows/unit.yml#L10-L12
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/test-ansible.yml around lines 10 - 12, Add
persist-credentials: false to every actions/checkout step in
.github/workflows/test-ansible.yml at lines 10-12 and 23-25,
.github/workflows/test-sanity.yml at lines 10-12, and .github/workflows/unit.yml
at lines 10-12; no other workflow behavior needs changing.
Source: Linters/SAST tools
| google.golang.org/protobuf v1.36.9 // indirect | ||
| google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect | ||
| google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect | ||
| google.golang.org/grpc v1.79.3 // indirect |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🌐 Web query:
GHSA-hrxh-6v49-42gf google.golang.org/grpc v1.79.3 advisory fixed version
💡 Result:
The security advisory GHSA-hrxh-6v49-42gf affects the google.golang.org/grpc package and identifies the fixed version as v1.82.1 [1][2][3]. The package version v1.79.3 is considered affected by this advisory, as the vulnerability impacts all versions of gRPC-Go prior to v1.82.1 [1][3][4]. Users are advised to upgrade their dependency to v1.82.1 or later to remediate the identified xDS RBAC and HTTP/2 transport vulnerabilities [1][3].
Citations:
- 1: GHSA-hrxh-6v49-42gf
- 2: GHSA-hrxh-6v49-42gf
- 3: https://cvereports.com/reports/GHSA-HRXH-6V49-42GF
- 4: https://pkg.go.dev/google.golang.org/grpc@v1.79.3
Upgrade google.golang.org/grpc to v1.82.1 or later. v1.79.3 is affected by GHSA-hrxh-6v49-42gf and should not remain in the module build list.
🧰 Tools
🪛 OSV Scanner (2.4.0)
[HIGH] 110-110: google.golang.org/grpc 1.79.3: gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@go.mod` at line 110, Update the google.golang.org/grpc dependency in go.mod
from v1.79.3 to v1.82.1 or later, and synchronize related module checksums or
dependency metadata so the module build list no longer includes the vulnerable
version.
Source: Linters/SAST tools
| @@ -1,4 +1,4 @@ | |||
| FROM registry.access.redhat.com/ubi9/ubi-minimal:9.7 AS basebuilder | |||
| FROM registry.access.redhat.com/ubi9/ubi-minimal:9.8 AS basebuilder | |||
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== file listing =="
git ls-files images/ansible-operator/pipfile.Dockerfile images/ansible-operator | sed 's#^`#-` #'
echo
echo "== Dockerfile lines =="
cat -n images/ansible-operator/pipfile.Dockerfile
echo
echo "== related image/container files =="
fd -a -t f 'Dockerfile' images/ansible-operator || true
rg -n --hidden --glob '!**/.git/**' 'pip-airlock|pip-audit|USER |ENTRYPOINT|pip install|pip wheel|lockfile' images/ansible-operator || trueRepository: openshift/ansible-operator-plugins
Length of output: 3492
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== README =="
cat -n images/ansible-operator/README.md
echo
echo "== main Dockerfile USER/runtime bits =="
sed -n '1,120p' images/ansible-operator/Dockerfile | cat -n
echo
echo "== non-root / DS-0002 references =="
rg -n 'non-root|DS-0002|USER_UID|USER |root' images/ansible-operatorRepository: openshift/ansible-operator-plugins
Length of output: 5471
🏁 Script executed:
#!/bin/bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
p = Path('images/ansible-operator/pipfile.Dockerfile')
text = p.read_text()
print("has USER instruction:", any(line.strip().startswith("USER ") for line in text.splitlines()))
print("has install pin for pip-audit:", 'pip-audit' in text and 'pip-audit==' in text)
print("has exact pip pin:", 'pip3 install --upgrade pip~=26.1.2' in text)
print("entrypoint:", [line for line in text.splitlines() if line.strip().startswith('ENTRYPOINT')][0])
PYRepository: openshift/ansible-operator-plugins
Length of output: 330
Run the helper image as non-root. The ENTRYPOINT still executes cp as root; add a non-root user and keep /tmp/pip-airlock writable so the generated Pipfile.lock isn’t written back to the bind mount as root-owned.
🧰 Tools
🪛 Trivy (0.72.0)
[error] 1-1: Image user should not be 'root'
Specify at least 1 USER command in Dockerfile with non-root user as argument
Rule: DS-0002
(IaC/Dockerfile)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@images/ansible-operator/pipfile.Dockerfile` at line 1, Add a non-root user in
the basebuilder image, grant that user write access to /tmp/pip-airlock, and
configure the image to run as that user so the ENTRYPOINT cp operation does not
create root-owned Pipfile.lock files.
Sources: Path instructions, Linters/SAST tools
| # No package names are hardcoded in the script beyond the RPM exclusion list | ||
| # and the cachi2-specific wheel==0.45.1 pin in the pre-build phase. |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Stale "hardcoded wheel pin" claim in two places. Build-isolation exact pins are now auto-discovered and probed against the pre-build constraint set (script Lines 824-884), so no wheel version is hardcoded; both descriptions still say otherwise.
openshift/Dockerfile.requirements#L33-L34: replace the "cachi2-specific wheel==0.45.1 pin" sentence with a note that isolation pins are auto-discovered from package metadata.openshift/hack/generate_requirements.py#L5-L7: drop "and cachi2-specific pins" from the module docstring's list of hardcoded assumptions.
📍 Affects 2 files
openshift/Dockerfile.requirements#L33-L34(this comment)openshift/hack/generate_requirements.py#L5-L7
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/Dockerfile.requirements` around lines 33 - 34, Update the
documentation describing hardcoded package assumptions: in
openshift/Dockerfile.requirements lines 33-34, replace the cachi2-specific wheel
pin statement with a note that build-isolation pins are auto-discovered from
package metadata; in openshift/hack/generate_requirements.py lines 5-7, remove
“and cachi2-specific pins” from the module docstring while leaving the script
behavior unchanged.
| # safety lives inside the pipenv virtualenv; try several invocation forms | ||
| for safety_cmd in ( | ||
| ["pipenv", "run", "safety", "check", "-r", str(txt_path)], | ||
| ["python3", "-m", "safety", "check", "-r", str(txt_path)], | ||
| ["safety", "check", "-r", str(txt_path)], | ||
| ): | ||
| check = subprocess.run(safety_cmd, capture_output=True, text=True) | ||
| if check.returncode != 1 or check.stderr.strip(): | ||
| # returncode==1 with no stderr → not a "command not found" | ||
| break | ||
| if "No such file" in check.stderr or "not found" in check.stderr.lower(): | ||
| continue # try next form | ||
| break | ||
|
|
||
| if check.returncode == 0: | ||
| print(f" No CVEs in {txt_path.name}") | ||
| continue |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
The Safety fallback chain is unreachable and can crash on a missing binary.
Two defects:
subprocess.runraisesFileNotFoundErrorwhen the executable does not exist; it never returns a "command not found" return code. Sopython3 -m safety/ baresafetyforms will abort the script rather than fall through to the next form.- The
breakon Line 1071 fires whenevercheck.stderris non-empty, which is exactly the case for a not-found error, so the"No such file"check on Line 1072 is dead code and the later forms are never tried.
Since Stage 5 runs after all requirement files are written, an unhandled exception here fails the Docker build and discards the generated artifacts.
🐛 Proposed fix
+ check = None
for safety_cmd in (
["pipenv", "run", "safety", "check", "-r", str(txt_path)],
["python3", "-m", "safety", "check", "-r", str(txt_path)],
["safety", "check", "-r", str(txt_path)],
):
- check = subprocess.run(safety_cmd, capture_output=True, text=True)
- if check.returncode != 1 or check.stderr.strip():
- # returncode==1 with no stderr → not a "command not found"
- break
- if "No such file" in check.stderr or "not found" in check.stderr.lower():
- continue # try next form
- break
+ try:
+ check = subprocess.run(safety_cmd, capture_output=True, text=True)
+ except FileNotFoundError:
+ continue # executable missing — try next form
+ if "No such file" in check.stderr or "not found" in check.stderr.lower():
+ continue # try next form
+ break
+
+ if check is None:
+ print(
+ f" WARNING: safety is not available; skipping CVE scan of {txt_path.name}.",
+ file=sys.stderr,
+ )
+ continue📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| # safety lives inside the pipenv virtualenv; try several invocation forms | |
| for safety_cmd in ( | |
| ["pipenv", "run", "safety", "check", "-r", str(txt_path)], | |
| ["python3", "-m", "safety", "check", "-r", str(txt_path)], | |
| ["safety", "check", "-r", str(txt_path)], | |
| ): | |
| check = subprocess.run(safety_cmd, capture_output=True, text=True) | |
| if check.returncode != 1 or check.stderr.strip(): | |
| # returncode==1 with no stderr → not a "command not found" | |
| break | |
| if "No such file" in check.stderr or "not found" in check.stderr.lower(): | |
| continue # try next form | |
| break | |
| if check.returncode == 0: | |
| print(f" No CVEs in {txt_path.name}") | |
| continue | |
| # safety lives inside the pipenv virtualenv; try several invocation forms | |
| check = None | |
| for safety_cmd in ( | |
| ["pipenv", "run", "safety", "check", "-r", str(txt_path)], | |
| ["python3", "-m", "safety", "check", "-r", str(txt_path)], | |
| ["safety", "check", "-r", str(txt_path)], | |
| ): | |
| try: | |
| check = subprocess.run(safety_cmd, capture_output=True, text=True) | |
| except FileNotFoundError: | |
| continue # executable missing — try next form | |
| if "No such file" in check.stderr or "not found" in check.stderr.lower(): | |
| continue # try next form | |
| break | |
| if check is None: | |
| print( | |
| f" WARNING: safety is not available; skipping CVE scan of {txt_path.name}.", | |
| file=sys.stderr, | |
| ) | |
| continue | |
| if check.returncode == 0: | |
| print(f" No CVEs in {txt_path.name}") | |
| continue |
🧰 Tools
🪛 ast-grep (0.44.1)
[error] 1067-1067: Use of unsanitized data to create processes
Context: subprocess.run(safety_cmd, capture_output=True, text=True)
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(os-system-unsanitized-data)
[error] 1067-1067: Command coming from incoming request
Context: subprocess.run(safety_cmd, capture_output=True, text=True)
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(subprocess-from-request)
🪛 Ruff (0.15.21)
[error] 1068-1068: subprocess call: check for execution of untrusted input
(S603)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/hack/generate_requirements.py` around lines 1062 - 1078, Update the
Safety invocation loop around safety_cmd so missing executables are caught as
FileNotFoundError and the next command form is attempted. Remove the premature
stderr-based break and only stop when the command executes successfully or
produces a non-missing-command result, while preserving the existing return-code
handling and artifact generation flow.
| rebase_work_branch="$version"-rebase-"$rebase_branch" | ||
| if git show-ref --verify --quiet refs/heads/"$rebase_work_branch"; then | ||
| echo "Branch $rebase_work_branch already exists, reusing it (assuming any pre-staged commits, e.g. cherry-picks, are intentional)." | ||
| git checkout "$rebase_work_branch" |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift
Synchronize reused branches with the updated base.
"$rebase_branch" was updated immediately before this block, but an existing "$rebase_work_branch" is checked out without verifying that it contains the updated base. On reruns after upstream changes, the resulting merge can omit commits from the target branch. Either merge the refreshed base into the reused branch or abort with a clear ancestry check.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/hack/rebase_upstream.sh` around lines 49 - 52, Update the
existing-branch path in the rebase_work_branch reuse logic to ensure the
checked-out branch contains the refreshed rebase_branch before continuing. Merge
the updated base into the reused branch, or perform an ancestry check and abort
with a clear message when it is not based on the refreshed target.
| if git show-ref --verify --quiet refs/heads/"$rebase_work_branch"; then | ||
| echo "Branch $rebase_work_branch already exists, reusing it (assuming any pre-staged commits, e.g. cherry-picks, are intentional)." | ||
| git checkout "$rebase_work_branch" | ||
| else | ||
| git checkout -b "$rebase_work_branch" || { echo "Failed to create branch $rebase_work_branch."; popd ; exit 1; } |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
Abort when reusing the branch fails.
Unlike the branch-creation path, the existing-branch git checkout is unchecked. If checkout fails—for example because the branch is active in another worktree—the script continues and may merge and commit on the current branch.
🧰 Tools
🪛 Shellcheck (0.11.0)
[warning] 54-54: Use 'popd ... || exit' or 'popd ... || return' in case popd fails.
(SC2164)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/hack/rebase_upstream.sh` around lines 50 - 54, Update the
existing-branch path around rebase_work_branch so git checkout failure aborts
the script immediately, matching the failure handling in the branch-creation
path. Preserve the current success behavior and ensure no merge or commit
proceeds when checkout fails.
| setuptools-rust==1.13.0 | ||
| # via -r /requirements-build.in | ||
| setuptools-scm==10.2.1 | ||
| # via | ||
| # -r /requirements-build.in | ||
| # hatch-vcs | ||
| trove-classifiers==2026.6.1.19 | ||
| # via | ||
| # -r requirements-build.in | ||
| # -r /requirements-build.in | ||
| # hatchling | ||
| wheel==0.46.3 | ||
| # via -r requirements-build.in | ||
| vcs-versioning==2.2.2 | ||
| # via | ||
| # -r /requirements-build.in | ||
| # setuptools-scm | ||
| wheel==0.47.0 | ||
| # via -r /requirements-build.in | ||
|
|
||
| # The following packages are considered to be unsafe in a requirements file: | ||
| setuptools==81.0.0 | ||
| setuptools==82.0.1 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
for p in setuptools-rust:1.13.0 vcs-versioning:2.2.2 setuptools:82.0.1 wheel:0.47.0 setuptools-scm:10.2.1; do
name="${p%%:*}"; ver="${p##*:}"
echo "=== $name $ver"
curl -s -X POST https://api.osv.dev/v1/query \
-d "{\"package\":{\"name\":\"$name\",\"ecosystem\":\"PyPI\"},\"version\":\"$ver\"}" \
| jq -r '.vulns[]? | "\(.id): \(.summary // "-")"'
doneRepository: openshift/ansible-operator-plugins
Length of output: 444
🏁 Script executed:
python3 - <<'PY'
import json, urllib.request
advisories = ["GHSA-h35f-9h28-mq5c", "PYSEC-2026-3447"]
for adv in advisories:
url = f"https://api.osv.dev/v1/vulns/{adv}"
print(f"=== {adv}")
try:
data = json.load(urllib.request.urlopen(url))
except Exception as e:
print("ERR", e)
continue
print("summary:", data.get("summary"))
for aff in data.get("affected", []):
pkg = aff.get("package", {})
print("package:", pkg.get("name"), pkg.get("ecosystem"))
for r in aff.get("ranges", []):
print("type:", r.get("type"))
for ev in r.get("events", []):
print(" event:", ev)
print("versions:", aff.get("versions"))
print("references:")
for ref in data.get("references", []):
print(" ", ref.get("type"), ref.get("url"))
PYRepository: openshift/ansible-operator-plugins
Length of output: 492
Bump setuptools off 82.0.1 setuptools==82.0.1 has a published advisory; move to a patched release.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/requirements-build.txt` around lines 56 - 74, Update the pinned
setuptools version in the requirements file from 82.0.1 to a patched release
that addresses the published advisory, keeping the existing unsafe-package entry
and formatting intact.
Source: Path instructions
| google-auth==2.55.0 | ||
| # via | ||
| # -r requirements.in | ||
| # -r /requirements.in | ||
| # kubernetes |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🌐 Web query:
google-auth 2.55.0 Python dependencies rsa requirement
💡 Result:
In google-auth version 2.55.0, the rsa library is listed as a required dependency, with the version constraint defined as >=3.1.4 and <5 [1][2]. While google-auth has transitioned to using the cryptography library as its primary backend for RSA operations [3], rsa remained a required dependency in version 2.55.0 to maintain backward compatibility and support existing functionality [4][3][2]. The library uses internal wrapper classes (such as RSASigner and RSAVerifier) that can leverage either the cryptography library or the rsa library [5][3]. In subsequent development, the project has aimed to reduce and eventually remove this hard dependency on rsa, moving it toward optional status in newer versions of the library [3][6][2].
Citations:
- 1: https://pypi.org/project/google-auth/2.55.0/
- 2: https://data.gpo.zugaina.org/gentoo/dev-python/google-auth/google-auth-2.55.0.ebuild
- 3: feat: add cryptography as required dependency googleapis/google-auth-library-python#1929
- 4: https://github.com/GoogleCloudPlatform/google-auth-library-python/blob/master/setup.py
- 5: https://googleapis.dev/python/google-auth/latest/reference/google.auth.crypt.rsa.html
- 6: https://pypi.org/project/google-auth/
🏁 Script executed:
set -euo pipefail
printf '\n[1] locate google-auth and rsa entries in openshift/requirements.txt\n'
rg -n '^(google-auth==|rsa==|pyasn1==|pyasn1-modules==)' openshift/requirements.txt || true
printf '\n[2] show the surrounding block around google-auth\n'
python3 - <<'PY'
from pathlib import Path
p = Path('openshift/requirements.txt')
lines = p.read_text().splitlines()
for i, line in enumerate(lines, 1):
if line.startswith('google-auth==') or line.startswith('rsa=='):
start = max(1, i-6)
end = min(len(lines), i+8)
print(f'\n--- lines {start}-{end} around line {i} ---')
for j in range(start, end+1):
print(f'{j:4}: {lines[j-1]}')
PY
printf '\n[3] check whether rsa appears anywhere in the file at all\n'
python3 - <<'PY'
from pathlib import Path
text = Path('openshift/requirements.txt').read_text()
print('rsa present:' , 'rsa==' in text or '\nrsa\n' in text or ' rsa' in text)
PYRepository: openshift/ansible-operator-plugins
Length of output: 834
Restore rsa to the google-auth runtime set. google-auth==2.55.0 still requires rsa>=3.1.4,<5, but rsa is missing from openshift/requirements.txt while its sibling deps are still pinned. A hermetic install will fail when google-auth is imported.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@openshift/requirements.txt` around lines 33 - 36, Update the pinned runtime
dependency set in requirements.txt by restoring the rsa package required by
google-auth==2.55.0, using the compatible rsa>=3.1.4,<5 constraint and retaining
the existing generated dependency annotations for the google-auth dependency
chain.
|
@mytreya-rh: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/assign |
Description of the change:*
Rebase this repo's main branch with upstream https://github.com/operator-framework/ansible-operator-plugins/releases/tag/v1.42.3 tag.
Changes done:
UPSTREAM: <carry>: automate hermetic build requirements generation) onto the rebase branch first, somake -f openshift/Makefile generate-requirementsuses the new Python-based generator (openshift/hack/generate_requirements.py) against the v1.42.3Pipfile/Pipfile.lockinstead of the old manual bash pipeline inopenshift/Dockerfile.requirements.openshift/hack/rebase_upstream.shto allow reusing a pre-existing<version>-rebase-<branch>branch, so the [WIP] UPSTREAM: <carry>: automate hermetic build requirements generation #79 cherry-pick could be staged before running the rest of the script.openshift/hack/rebase_upstream.sh v1.42.3, which merged upstream tagv1.42.3(no conflicts), rango mod tidy && go mod vendor, regeneratedopenshift/release/ansible/ansible_collections(only benign galaxy metadata URL diffs), and regeneratedopenshift/requirements*.txt/openshift/Pipfile.lockvia the new generator.Motivation for the change:
Pick up upstream v1.42.3, which bumps the Go toolchain to 1.26.3 and updates several Go/Python dependencies for CVE fixes (cryptography, urllib3, idna, requests, grpc, pyasn1, pip/pipenv, ubi9-minimal, etc.), while also landing the automated hermetic build-requirements generation from [WIP] UPSTREAM: <carry>: automate hermetic build requirements generation #79 ahead of the dependency regeneration so the new requirements files are produced by the maintained script rather than the manual bash pipeline.
Summary by CodeRabbit