build: image for PR #43 (compute class features) — do not merge - #44
sagrawal-byte wants to merge 4 commits into
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
Broly Security ScanWarning
Note Summary 18 actionable finding(s) in this PR
10 highest-priority actionable rows in the table below (critical/high first, then top medium). 2 finding(s) below the
Fix Suggestionscode injection via template expansion — .github/workflows/container-images-1.0.yaml:64Do not pass untrusted PR or issue fields directly into code injection via template expansion — .github/workflows/container-images-1.0.yaml:67Do not pass untrusted PR or issue fields directly into code injection via template expansion — .github/workflows/container-images-1.0.yaml:69Do not pass untrusted PR or issue fields directly into unpinned action reference — .github/workflows/container-images-1.0.yaml:41Pin actions/checkout to the commit v4 currently resolves to: --- a/.github/workflows/container-images-1.0.yaml
+++ b/.github/workflows/container-images-1.0.yaml
@@ -38,7 +38,7 @@
contents: read
steps:
- name: Checkout
- uses: actions/checkout@v4
+ uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
# PRs: use the tip of the PR branch so the image tag matches the commit under review.
ref: ${{ github.event.pull_request.head.sha || github.sha }}unpinned action reference — .github/workflows/container-images-1.0.yaml:76Pin actions/setup-go to the commit v5 currently resolves to: --- a/.github/workflows/container-images-1.0.yaml
+++ b/.github/workflows/container-images-1.0.yaml
@@ -73,7 +73,7 @@
fi
- name: Set up Go
- uses: actions/setup-go@v5
+ uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
with:
go-version-file: go.mod
Dismiss false positivesTick a box to dismiss the finding; untick it to bring the finding back. That is the same as replying
Note Re-scan this PR anytime with
|
| contents: read | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 |
| - name: Whether to push to Docker Hub | ||
| id: should-push | ||
| run: | | ||
| if [ "${{ github.event_name }}" = "push" ] && [ "${{ github.ref }}" = "refs/heads/main" ]; then |
| if [ "${{ github.event_name }}" = "push" ] && [ "${{ github.ref }}" = "refs/heads/main" ]; then | ||
| echo "push=true" >> "$GITHUB_OUTPUT" | ||
| elif [ "${{ github.event_name }}" = "pull_request" ] && \ | ||
| [ "${{ github.event.pull_request.head.repo.full_name }}" = "${{ github.repository }}" ]; then |
| elif [ "${{ github.event_name }}" = "pull_request" ] && \ | ||
| [ "${{ github.event.pull_request.head.repo.full_name }}" = "${{ github.repository }}" ]; then | ||
| echo "push=true" >> "$GITHUB_OUTPUT" | ||
| elif [ "${{ github.event_name }}" = "workflow_dispatch" ] && [ "${{ github.ref }}" = "refs/heads/main" ]; then |
| fi | ||
|
|
||
| - name: Set up Go | ||
| uses: actions/setup-go@v5 |
| @@ -1,4 +1,4 @@ | |||
| module github.com/SlinkyProject/slurm-operator | |||
| module github.com/togethercomputer/slurm-operator | |||
| @@ -1,4 +1,4 @@ | |||
| module github.com/SlinkyProject/slurm-operator | |||
| module github.com/togethercomputer/slurm-operator | |||
| - name: Checkout | ||
| uses: actions/checkout@v4 | ||
| with: | ||
| # PRs: use the tip of the PR branch so the image tag matches the commit under review. | ||
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| fetch-depth: 0 |
|
|
||
| - name: Build and push images | ||
| if: steps.should-push.outputs.push == 'true' | ||
| run: make push-images VERSION="${{ steps.image-version.outputs.version }}" |
| # Push path: one bake (--push) only. Non-push: make build = build-images + build-chart (single bake). | ||
| - name: Build (images + charts, no registry push) | ||
| if: steps.should-push.outputs.push != 'true' | ||
| run: make build VERSION="${{ steps.image-version.outputs.version }}" |
|
Branch conflicts with slurm-1.0-together-changes so the image workflow can't run; building locally instead. |
Draft PR to trigger the container-images-1.0 workflow, which builds and pushes
togethercomputer/slurm-operator:1.0.0-dev-<shortsha>for testing PR #43 on staging. Will be closed after testing.Made with Cursor