Repository navigation
ci: pin the runner image to ubuntu-24.04 - #130
singlerider wants to merge 6 commits into
Conversation
ubuntu-latest is a label GitHub moves. The image changes under us and a green pipeline turns red on a morning nobody touched the code. Pinning to ubuntu-24.04 means the runner moves when we move it. Action refs are untouched; the version-tagged ones stay as they are and Dependabot keeps watching them.
|
@en0f review when you have a minute. Last repo in the family still on |
|
Approved. Only one note. The PR can't merge green yet: The lint job fails, so the test job never runs. Ruff reports 70 errors in the existing code (for example RUF010 in webcap/webscreenshot.py:163). This PR didn't cause them. The workflow installs ruff with pipx install ruff and no version pin, so a newer ruff release is failing code that used to pass. PR #129 (the AGPL relicense) fails the same way on ubuntu-latest. To unblock it, pin ruff in the lint step or fix the ruff errors on dev, then re-run. This PR is worth landing soon: the runner warns that ubuntu-latest switches to Ubuntu 26 starting October 19, 2026. |
The lint job installed ruff with no version, so it picked up 0.16.9, which flags 70 errors in existing code. Lint failed and the test matrix never ran on the new ubuntu-24.04 runner. Pin ruff with == in the workflow and in the dev dependency group, at the 0.11.10 already locked in poetry.lock. That version passes ruff check and ruff format clean on this branch. Bump it deliberately in a commit that also fixes what the new version flags.
Welcome to Codecov 🎉Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests. Thanks for integrating Codecov - We've got you covered ☂️ |
|
@en0f re-requesting review: |
On ubuntu-24.04 chromium-browser is a snap transitional package whose install fails in the runner, which broke every test job once the runner was pinned. The image already ships google-chrome, which webcap's binary detection finds.
AppArmor restricts unprivileged user namespaces on 24.04, so Chrome aborted with 'No usable sandbox'. Lift the restriction on the runner rather than running Chrome with --no-sandbox.
|
Green and mergeable. Part of blacklanternsecurity/bbot-enterprise#149. |
|
@liquidsec needs a review and merge from someone with write access. |
`ruff format` without --check rewrote files in the runner and always passed, so formatting was never enforced. The ruff pin was also repeated in the workflow; install the locked dev group instead.
|
@liquidsec @shart123456 @en0f review requested. I can't add reviewers on this repo (read-only access). |
Remove the publish job from tests.yml. On every push to master it
published to PyPI with a long-lived token and then ran git tag and git
push of the tag from CI.
Add publish.yml from the asndb template: runs only on v* tags, checks
the tag matches the poetry-dynamic-versioning version from a full
history checkout, reuses tests.yml through workflow_call, publishes
with PyPI trusted publishing in the pypi environment, and cuts a GitHub
release with an SPDX SBOM.
Drop the v0.1.{distance} format override so an exact vX.Y.Z tag yields
version X.Y.Z instead of a distance-derived number.
tests.yml now triggers on pushes to master only plus pull_request and
workflow_call, runs with contents: read, and pins every action to a SHA.
Refs: blacklanternsecurity/bbot-enterprise#139
Refs: blacklanternsecurity/bbot-enterprise#155
Refs: blacklanternsecurity/bbot-enterprise#150
|
Superseded by #132, which pins the runner and moves lint and tests to the shared workflows. The two conflict in tests.yml, publish.yml and pyproject.toml. |
ubuntu-latestis a label GitHub moves. The image behind it changes on GitHub's schedule, and a pipeline nobody touched goes red on a Tuesday. This pins every job toubuntu-24.04so the runner moves when we move it.Action refs are left alone. Version-tagged actions stay on their tags and Dependabot keeps bumping them.
Validation
actionlintclean on the changed workflows. No logic, matrix, or step changes: only theruns-on:value.Part of https://github.com/blacklanternsecurity/bbot-enterprise/issues/149.