Repository navigation
Pin CI tooling to restore build, lint, and image loading - #5602
Conversation
|
Thanks for tracking these down @ekamran β this PR correctly identifies all three unpinned-tooling failures. A few notes from reviewing it: The hadolint The lint fix is split out as #5605 so it can land immediately: because this PR touches On the Remaining red on this PR (API tests, catalog tests, Nuxt |
The upstream hadolint-docker hook leaves the image tag floating at `latest`, so every lint run pulled the newest hadolint regardless of the pinned `rev`. A new release introduced rule DL3066, which fails the required "Lint files" job on every PR. hadolint v2.12.0 with the repository's existing .hadolint.yaml produces no findings. Split out from #5602 (thanks @ekamran) so the lint fix can land without triggering the test suites that are failing for unrelated reasons. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The Dockerfile installed whatever pipenv was newest. pipenv 2026.4.0 started normalizing package names when computing the Pipfile hash, so the existing Pipfile.lock no longer validates and pipenv install --deploy aborts. Since that release the ingestion_server image fails to build on main and on every open PR. Pinning to 2026.2.2, the last release that accepts the current lock, makes the build reproducible again. The long term replacement for Pipenv here is tracked in WordPress#4658.
The action installs @actions/artifact unpinned and then loads it with require(). Version 6 is ESM only and its exports map has no CommonJS entry, so every job using this action fails at the Load Docker images step with ERR_PACKAGE_PATH_NOT_EXPORTED before its tests run. Pin to 5.0.3, the last release that ships a CommonJS entry point, and note the reason inline so the pin is not removed as stale.
python:3.12-slim now resolves to Debian 13 (trixie), where the audiowaveform 1.10.1 .deb (built for Debian 12) fails to install. The failure is masked by the `|| apt-get --fix-broken install` fallback, so the image builds without the binary and the waveform tests fail with FileNotFoundError. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
minio/mc:latest removed the legacy `mc config host add` command, so the load_to_s3 container failed to create the test buckets and the catalog tests failed with NoSuchBucket. `mc alias set` is the long-supported replacement; the images are pinned to current releases so they can't drift again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
corepack 0.31.0 predates the npm registry's latest signing key rotation, so its pnpm download fails signature verification in the setup-node step (ERR_ASSERTION). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
ec721cc to
0932b16
Compare
|
Rebased onto
|
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Thanks @obenland, and for splitting the lint half out so it could land on its own. You were right about the failure-threshold hunk. With the image pinned to v2.12.0 there are no findings to suppress, so it was only adding noise. The three extra pins are the useful part here. I had traced the failures lint was still reporting, not the ones its breakage was hiding. I have rebased #5585 onto main, so the two temporary pins I was carrying there are gone and it is back to just the docs change. |
Every open PR in this repository currently carries red CI for reasons unrelated to its changes. I traced them while trying to get #5585 reviewed. The common pattern is CI tooling installed unpinned at runtime, so quiet upstream releases changed CI behaviour under the repository.
This PR pins three of those runtime tools.
1. ingestion_server Docker build, failing since pipenv 2026.4.0
The Dockerfile installs whatever pipenv is newest. pipenv 2026.4.0 started normalizing package names when computing the Pipfile hash, so the existing Pipfile.lock no longer validates and
pipenv install --deployaborts.I bisected the releases: 2026.2.2 is the last one that accepts the current lock, so this pins to it. Regenerating the lock would also work but touches every pinned dependency, and the long term fix is the planned move of this service off Pipenv in #4658.
Verified: the two-stage build fails on current main and passes with the pin.
2. Dockerfile lint job, failing since a recent hadolint release
The hadolint pre-commit hook pins the hook repository at v2.12.0 but leaves the docker image tag floating, so every run pulls the newest hadolint. A newer release added DL3066, an informational note that fires on six pre-existing Dockerfiles, and with no failure-threshold configured hadolint fails on any finding.
Two changes: the image is pinned to the same version as the hook rev so results are reproducible, and
failure-thresholdis set towarningso informational advice stays visible in the lint output without failing the job.Verified with both the pinned and the latest image, and a warning-level violation still fails.
3. Load Docker images, failing since @actions/artifact v6
.github/actions/load-imginstalled@actions/artifactunpinned and then loaded it withrequire().@actions/artifactv6 is ESM-only and its exports map has no CommonJS entry, so the action failed with:This pins
@actions/artifactto 5.0.3, the last release that still provides the CommonJS entry point used by the existing script.Verified on this PR: the previous
Load Docker imagesfailure is gone, Docker image loading now proceeds, andRun tests for ingestion-servernow passes.Current CI status
This PR still has failures, but they are no longer the three CI-tooling failures fixed here.
Code-level failures that remain:
Run tests for the APIfails becauseaudiowaveformis missing. This one is not new: it also fails on the previous commit of this PR and on Clarify API key registration fieldsΒ #5585, which only touches documentation.Run Nuxt checks (frontend_init)fails while Corepack downloadspnpm-10.2.0withAssertionError [ERR_ASSERTION]: assert(!this.paused).Run tests for the catalogfails on missing S3 bucketmigrated-cccatalog-archives.The last two could not run at all before this PR, because their jobs stopped earlier at
Load Docker images.There are also maintainer-only label check failures.
So this PR does not make the full matrix green, but it removes three independent CI rot issues and gets the affected jobs past the blockers they previously could not pass.