Skip to content

build: image for PR #43 (compute class features) — do not merge - #44

Closed
sagrawal-byte wants to merge 4 commits into
slurm-1.0-together-changesfrom
sagrawal/reconcile-compute-class-features
Closed

sagrawal-byte wants to merge 4 commits into
slurm-1.0-together-changesfrom
sagrawal/reconcile-compute-class-features

Conversation

@sagrawal-byte

Copy link
Copy Markdown

Draft PR to trigger the container-images-1.0 workflow, which builds and pushes togethercomputer/slurm-operator:1.0.0-dev-<shortsha> for testing PR #43 on staging. Will be closed after testing.

Made with Cursor

@broly-code-security-scanner

Copy link
Copy Markdown

Broly Security Scan

Warning

⚠️ Potential results — Broly is still completing analysis or verification. This comment will update automatically.
Files pending AI analysis: 5; findings pending verification: 18.

Note

Summary

18 actionable finding(s) in this PR
20 total in scan · 0 dismissed false positives

  • 🟠 9 high
  • 🟡 9 medium

10 highest-priority actionable rows in the table below (critical/high first, then top medium).

2 finding(s) below the medium reporting threshold are not listed above — see the repository Security tab for the full set.

Severity Scanner Issue Location Dismiss Verdict
🟠 HIGH GH Actions code injection via template expansion .github/workflows/container-images-1.0.yaml:64 d1 ⚠️ Not verified
🟠 HIGH GH Actions code injection via template expansion .github/workflows/container-images-1.0.yaml:67 d2 ⚠️ Not verified
🟠 HIGH GH Actions code injection via template expansion .github/workflows/container-images-1.0.yaml:69 d3 ⚠️ Not verified
🟠 HIGH GH Actions unpinned action reference .github/workflows/container-images-1.0.yaml:41 d4 ⚠️ Not verified
🟠 HIGH GH Actions unpinned action reference .github/workflows/container-images-1.0.yaml:76 d5 ⚠️ Not verified
🟡 MEDIUM SCA golang.org/x/crypto@0.43.0 — 34 vulnerabilities
(worst: GHSA-45gg-vh54-h5m9)
→ >= 0.56.0
go.mod:1 d15 ⚠️ Not verified
🟡 MEDIUM SCA golang.org/x/net@0.46.0 — 9 vulnerabilities
(worst: GHSA-5cv4-jp36-h3mw)
→ >= 0.56.0
go.mod:1 d11 ⚠️ Not verified
🟡 MEDIUM SCA github.com/getkin/kin-openapi@0.133.0 — 8
vulnerabilities (worst: GHSA-jpcw-4wr7-c3vq)
→ >= 0.144.0
go.mod:1 d16 ⚠️ Not verified
🟡 MEDIUM SCA go.opentelemetry.io/otel@1.38.0 — 2
vulnerabilities (worst: GHSA-mh2q-q3fh-2475)
→ >= 1.41.0
go.mod:1 d12 🔺 TRUE_POSITIVE · Confidence: HIGH
🟡 MEDIUM SCA k8s.io/kubernetes@1.34.1 — 4 vulnerabilities
(worst: GHSA-r6j8-c6r2-37rr)
→ >= 1.34.2
go.mod:1 d18 ⚠️ Not verified

Fix Suggestions

code injection via template expansion — .github/workflows/container-images-1.0.yaml:64

Do not pass untrusted PR or issue fields directly into run: scripts; assign them to env vars and reference the env var. Docs: https://docs.zizmor.sh/audits/#template-injection

code injection via template expansion — .github/workflows/container-images-1.0.yaml:67

Do not pass untrusted PR or issue fields directly into run: scripts; assign them to env vars and reference the env var. Docs: https://docs.zizmor.sh/audits/#template-injection

code injection via template expansion — .github/workflows/container-images-1.0.yaml:69

Do not pass untrusted PR or issue fields directly into run: scripts; assign them to env vars and reference the env var. Docs: https://docs.zizmor.sh/audits/#template-injection

unpinned action reference — .github/workflows/container-images-1.0.yaml:41

Pin actions/checkout to the commit v4 currently resolves to: actions/checkout@11d5960a326750d5838078e36cf38b85af677262. The tag stays in a trailing comment so the version remains readable; a tag can be repointed at new code, a commit cannot.

--- a/.github/workflows/container-images-1.0.yaml
+++ b/.github/workflows/container-images-1.0.yaml
@@ -38,7 +38,7 @@
       contents: read
     steps:
       - name: Checkout
-        uses: actions/checkout@v4
+        uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
         with:
           # PRs: use the tip of the PR branch so the image tag matches the commit under review.
           ref: ${{ github.event.pull_request.head.sha || github.sha }}
unpinned action reference — .github/workflows/container-images-1.0.yaml:76

Pin actions/setup-go to the commit v5 currently resolves to: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff. The tag stays in a trailing comment so the version remains readable; a tag can be repointed at new code, a commit cannot.

--- a/.github/workflows/container-images-1.0.yaml
+++ b/.github/workflows/container-images-1.0.yaml
@@ -73,7 +73,7 @@
           fi
 
       - name: Set up Go
-        uses: actions/setup-go@v5
+        uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5
         with:
           go-version-file: go.mod
 

Dismiss false positives

Tick a box to dismiss the finding; untick it to bring the finding back. That is the same as replying /broly dismiss d1 and /broly undismiss d1. To record why it is a false positive, reply with /broly dismiss d1: your reason instead — Broly reuses those reasons to triage similar findings across the org.

  • d1 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:64 · code injection via template expansion
  • d2 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:67 · code injection via template expansion
  • d3 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:69 · code injection via template expansion
  • d4 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:41 · unpinned action reference
  • d5 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:76 · unpinned action reference
  • d6 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:87 · unpinned action reference
  • d7 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:92 · unpinned action reference
  • d8 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:95 · unpinned action reference
  • d9 · 🟠 HIGH     · .github/workflows/container-images-1.0.yaml:99 · unpinned action reference
  • d10 · 🟡 MEDIUM   · .github/workflows/container-images-1.0.yaml:40 · credential persistence through GitHub Actions artifacts
  • d11 · 🟡 MEDIUM   · go.mod:1 · golang.org/x/net@0.46.0 — 9 vulnerabilities (worst: GHSA-5cv4-jp36-h3mw)
  • d12 · 🟡 MEDIUM   · go.mod:1 · go.opentelemetry.io/otel@1.38.0 — 2 vulnerabilities (worst: GHSA-mh2q-q3fh-...
  • d13 · 🟡 MEDIUM   · go.mod:1 · stdlib@1.25.3 — 35 vulnerabilities (worst: GO-2025-4155)
  • d14 · 🟡 MEDIUM   · go.mod:1 · GO-2026-5024: golang.org/x/sys@0.37.0
  • d15 · 🟡 MEDIUM   · go.mod:1 · golang.org/x/crypto@0.43.0 — 34 vulnerabilities (worst: GHSA-45gg-vh54-h5m9)
  • d16 · 🟡 MEDIUM   · go.mod:1 · github.com/getkin/kin-openapi@0.133.0 — 8 vulnerabilities (worst: GHSA-jpcw...
  • d17 · 🟡 MEDIUM   · go.mod:1 · GO-2026-5970: golang.org/x/text@0.30.0
  • d18 · 🟡 MEDIUM   · go.mod:1 · k8s.io/kubernetes@1.34.1 — 4 vulnerabilities (worst: GHSA-r6j8-c6r2-37rr)

Note

Re-scan this PR anytime with /broly scan — useful after /broly undismiss, or to refresh findings without a new push.

Broly — SAST (zai-org/GLM-5.3-Flash) · Secrets · SCA · IaC · GH Actions · Base Images · Supply Chain Threats · Exploit Chains · Adversarial Verification

We're continuously improving Broly's accuracy and finding quality — your feedback is valuable. False positives, missed findings, bugs, and feature requests all welcome.

Ask in #security-engineering   Powered by Together AI

contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Whether to push to Docker Hub
id: should-push
run: |
if [ "${{ github.event_name }}" = "push" ] && [ "${{ github.ref }}" = "refs/heads/main" ]; then
if [ "${{ github.event_name }}" = "push" ] && [ "${{ github.ref }}" = "refs/heads/main" ]; then
echo "push=true" >> "$GITHUB_OUTPUT"
elif [ "${{ github.event_name }}" = "pull_request" ] && \
[ "${{ github.event.pull_request.head.repo.full_name }}" = "${{ github.repository }}" ]; then
elif [ "${{ github.event_name }}" = "pull_request" ] && \
[ "${{ github.event.pull_request.head.repo.full_name }}" = "${{ github.repository }}" ]; then
echo "push=true" >> "$GITHUB_OUTPUT"
elif [ "${{ github.event_name }}" = "workflow_dispatch" ] && [ "${{ github.ref }}" = "refs/heads/main" ]; then
fi

- name: Set up Go
uses: actions/setup-go@v5
Comment thread go.mod
@@ -1,4 +1,4 @@
module github.com/SlinkyProject/slurm-operator
module github.com/togethercomputer/slurm-operator
Comment thread go.mod
@@ -1,4 +1,4 @@
module github.com/SlinkyProject/slurm-operator
module github.com/togethercomputer/slurm-operator
Comment on lines +40 to +45
- name: Checkout
uses: actions/checkout@v4
with:
# PRs: use the tip of the PR branch so the image tag matches the commit under review.
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0

- name: Build and push images
if: steps.should-push.outputs.push == 'true'
run: make push-images VERSION="${{ steps.image-version.outputs.version }}"
# Push path: one bake (--push) only. Non-push: make build = build-images + build-chart (single bake).
- name: Build (images + charts, no registry push)
if: steps.should-push.outputs.push != 'true'
run: make build VERSION="${{ steps.image-version.outputs.version }}"
@sagrawal-byte

Copy link
Copy Markdown
Author

Branch conflicts with slurm-1.0-together-changes so the image workflow can't run; building locally instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants