Skip to content

Pin CI tooling to restore build, lint, and image loading - #5602

Merged
obenland merged 6 commits into
WordPress:mainfrom
ekamran:fix/pin-pipenv-ingestion-server
Aug 25, 2026
Merged

obenland merged 6 commits into
WordPress:mainfrom
ekamran:fix/pin-pipenv-ingestion-server

Conversation

@ekamran

@ekamran ekamran commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Every open PR in this repository currently carries red CI for reasons unrelated to its changes. I traced them while trying to get #5585 reviewed. The common pattern is CI tooling installed unpinned at runtime, so quiet upstream releases changed CI behaviour under the repository.

This PR pins three of those runtime tools.

1. ingestion_server Docker build, failing since pipenv 2026.4.0

The Dockerfile installs whatever pipenv is newest. pipenv 2026.4.0 started normalizing package names when computing the Pipfile hash, so the existing Pipfile.lock no longer validates and pipenv install --deploy aborts.

I bisected the releases: 2026.2.2 is the last one that accepts the current lock, so this pins to it. Regenerating the lock would also work but touches every pinned dependency, and the long term fix is the planned move of this service off Pipenv in #4658.

Verified: the two-stage build fails on current main and passes with the pin.

2. Dockerfile lint job, failing since a recent hadolint release

The hadolint pre-commit hook pins the hook repository at v2.12.0 but leaves the docker image tag floating, so every run pulls the newest hadolint. A newer release added DL3066, an informational note that fires on six pre-existing Dockerfiles, and with no failure-threshold configured hadolint fails on any finding.

Two changes: the image is pinned to the same version as the hook rev so results are reproducible, and failure-threshold is set to warning so informational advice stays visible in the lint output without failing the job.

Verified with both the pinned and the latest image, and a warning-level violation still fails.

3. Load Docker images, failing since @actions/artifact v6

.github/actions/load-img installed @actions/artifact unpinned and then loaded it with require().

@actions/artifact v6 is ESM-only and its exports map has no CommonJS entry, so the action failed with:

ERR_PACKAGE_PATH_NOT_EXPORTED

This pins @actions/artifact to 5.0.3, the last release that still provides the CommonJS entry point used by the existing script.

Verified on this PR: the previous Load Docker images failure is gone, Docker image loading now proceeds, and Run tests for ingestion-server now passes.

Current CI status

This PR still has failures, but they are no longer the three CI-tooling failures fixed here.

Code-level failures that remain:

  • Run tests for the API fails because audiowaveform is missing. This one is not new: it also fails on the previous commit of this PR and on Clarify API key registration fieldsΒ #5585, which only touches documentation.
  • Run Nuxt checks (frontend_init) fails while Corepack downloads pnpm-10.2.0 with AssertionError [ERR_ASSERTION]: assert(!this.paused).
  • Run tests for the catalog fails on missing S3 bucket migrated-cccatalog-archives.

The last two could not run at all before this PR, because their jobs stopped earlier at Load Docker images.

There are also maintainer-only label check failures.

So this PR does not make the full matrix green, but it removes three independent CI rot issues and gets the affected jobs past the blockers they previously could not pass.

@ekamran
ekamran requested review from a team as code owners August 20, 2026 07:13
@ekamran
ekamran requested review from dhruvkb and krysal and removed request for a team August 20, 2026 07:13
@openverse-bot openverse-bot added the 🚦 status: awaiting triage Has not been triaged & therefore, not ready for work label Aug 20, 2026
@openverse-bot openverse-bot moved this to πŸ‘€ Needs Review in Openverse PRs Aug 20, 2026
@openverse-bot openverse-bot added the 🏷 status: label work required Needs proper labelling before it can be worked on label Aug 20, 2026
@ekamran ekamran changed the title Pin Pipenv and hadolint to restore build and lint CI Pin CI tooling to restore build, lint, and image loading Aug 24, 2026
@openverse-bot openverse-bot added the 🧱 stack: mgmt Related to repo management and automations label Aug 24, 2026
@obenland obenland added πŸ€– aspect: dx Concerns developers' experience with the codebase πŸ›  goal: fix Bug fix 🟧 priority: high Stalls work on the project or its dependents labels Aug 25, 2026
@obenland

Copy link
Copy Markdown
Member

Thanks for tracking these down @ekamran β€” this PR correctly identifies all three unpinned-tooling failures. A few notes from reviewing it:

The hadolint entry: pin is the complete lint fix on its own. I verified locally that hadolint v2.12.0 with the repo's existing .hadolint.yaml produces zero findings across all seven Dockerfiles (exit 0). The failure-threshold: warning addition is therefore unnecessary β€” and its comment is slightly misleading, since the version pin already prevents new rules from future releases appearing. I'd suggest dropping that hunk; if an info-level rule ever does need waiving, the repo's existing per-rule ignored: pattern keeps it visible.

The lint fix is split out as #5605 so it can land immediately: because this PR touches ingestion_server/Dockerfile, it triggers the full API/catalog/Nuxt suites, which are currently failing for unrelated reasons and are required checks β€” the lint blockage affects every open PR (including several stuck Renovate security updates), so it shouldn't wait on those. Once #5605 merges, rebasing this PR will shrink it to the pipenv and @actions/artifact pins.

On the @actions/artifact@5.0.3 pin: the reasoning (v6 is ESM-only) is correct. Longer term the dependency would be better declared in the root package.json so Renovate manages it and the lockfile pins it β€” right now it lives only in a shell string, the same unmanaged-drift class this PR fixes elsewhere. Fine as a follow-up, since load-img currently skips the install recipe and would need a small change to use it.

Remaining red on this PR (API tests, catalog tests, Nuxt frontend_init β€” the latter is the Corepack signature-verification breakage when downloading pnpm) is pre-existing and unrelated to these changes; it needs separate fixes before this can merge.

obenland added a commit that referenced this pull request Aug 25, 2026
The upstream hadolint-docker hook leaves the image tag floating at
`latest`, so every lint run pulled the newest hadolint regardless of
the pinned `rev`. A new release introduced rule DL3066, which fails
the required "Lint files" job on every PR. hadolint v2.12.0 with the
repository's existing .hadolint.yaml produces no findings.

Split out from #5602 (thanks @ekamran) so the lint fix can land without
triggering the test suites that are failing for unrelated reasons.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@obenland obenland added the 🧱 stack: ingestion server Related to the ingestion/data refresh server label Aug 25, 2026
ekamran and others added 5 commits August 25, 2026 15:29
The Dockerfile installed whatever pipenv was newest. pipenv 2026.4.0
started normalizing package names when computing the Pipfile hash,
so the existing Pipfile.lock no longer validates and
pipenv install --deploy aborts. Since that release the
ingestion_server image fails to build on main and on every open PR.

Pinning to 2026.2.2, the last release that accepts the current lock,
makes the build reproducible again. The long term replacement for
Pipenv here is tracked in WordPress#4658.
The action installs @actions/artifact unpinned and then loads it with
require(). Version 6 is ESM only and its exports map has no CommonJS
entry, so every job using this action fails at the Load Docker images
step with ERR_PACKAGE_PATH_NOT_EXPORTED before its tests run.

Pin to 5.0.3, the last release that ships a CommonJS entry point, and
note the reason inline so the pin is not removed as stale.
python:3.12-slim now resolves to Debian 13 (trixie), where the
audiowaveform 1.10.1 .deb (built for Debian 12) fails to install. The
failure is masked by the `|| apt-get --fix-broken install` fallback,
so the image builds without the binary and the waveform tests fail
with FileNotFoundError.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
minio/mc:latest removed the legacy `mc config host add` command, so
the load_to_s3 container failed to create the test buckets and the
catalog tests failed with NoSuchBucket. `mc alias set` is the
long-supported replacement; the images are pinned to current releases
so they can't drift again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
corepack 0.31.0 predates the npm registry's latest signing key
rotation, so its pnpm download fails signature verification in the
setup-node step (ERR_ASSERTION).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@obenland
obenland force-pushed the fix/pin-pipenv-ingestion-server branch from ec721cc to 0932b16 Compare August 25, 2026 20:34
@obenland
obenland requested a review from a team as a code owner August 25, 2026 20:34
@obenland

Copy link
Copy Markdown
Member

Rebased onto main and extended this PR so the whole pipeline can go green (pushed with maintainer edit access β€” your two pins are unchanged, @ekamran):

  • Kept: the pipenv pin and the @actions/artifact@5.0.3 pin, as-is.
  • Dropped in the rebase: the hadolint hunk β€” the image pin landed via Pin hadolint Docker image to match the hook revΒ #5605, and with hadolint back at v2.12.0 there are no findings to suppress, so the failure-threshold isn't needed.
  • Added three more pins for the failures that lint's breakage had been masking (each root cause verified locally before committing):
    • api/Dockerfile: pin base images to -bookworm. python:3.12-slim now resolves to Debian 13, where the audiowaveform 1.10.1 .deb (built for Debian 12) fails to install β€” masked by the || apt-get --fix-broken install fallback, so images build without the binary and the waveform tests fail. (Recent runs sometimes pass when the GHA build cache still holds pre-drift layers.)
    • catalog/compose.yml + docker/minio/load_to_s3_entrypoint.sh: pin minio/minio and minio/mc and switch the removed mc config host add to mc alias set β€” newer mc dropped the legacy command, so test buckets were never created (NoSuchBucket in the catalog tests).
    • .github/actions/setup-env: corepack 0.31.0 β†’ 0.35.0 β€” 0.31.0 predates the npm registry's latest signing-key rotation, so its pnpm download fails signature verification (the Nuxt job's ERR_ASSERTION).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@obenland
obenland merged commit 2affe89 into WordPress:main Aug 25, 2026
53 checks passed
@github-project-automation github-project-automation Bot moved this from πŸ‘€ Needs Review to 🀝 Merged in Openverse PRs Aug 25, 2026
@ekamran

ekamran commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Thanks @obenland, and for splitting the lint half out so it could land on its own.

You were right about the failure-threshold hunk. With the image pinned to v2.12.0 there are no findings to suppress, so it was only adding noise.

The three extra pins are the useful part here. I had traced the failures lint was still reporting, not the ones its breakage was hiding.

I have rebased #5585 onto main, so the two temporary pins I was carrying there are gone and it is back to just the docs change.

@ekamran
ekamran deleted the fix/pin-pipenv-ingestion-server branch August 26, 2026 05:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

πŸ€– aspect: dx Concerns developers' experience with the codebase πŸ›  goal: fix Bug fix 🟧 priority: high Stalls work on the project or its dependents 🧱 stack: ingestion server Related to the ingestion/data refresh server 🧱 stack: mgmt Related to repo management and automations 🚦 status: awaiting triage Has not been triaged & therefore, not ready for work 🏷 status: label work required Needs proper labelling before it can be worked on

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants