Skip to content

[ci-coach] Fix stale docker action pins in wasm golden test fixture - #61359

Merged
pelikhan merged 1 commit into
mainfrom
fix/wasm-golden-docker-action-pins-4fc920ddfc8095ae
Sep 16, 2026
Merged

pelikhan merged 1 commit into
mainfrom
fix/wasm-golden-docker-action-pins-4fc920ddfc8095ae

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

CI Optimization Proposal — Pre-flight Repair

Summary

test-unit pre-flight validation was failing with exit code 1. Root cause: TestWasmGolden_CompileFixtures/smoke-copilot in pkg/workflow was comparing against a stale golden file. The recent actions-update PR (#61303) bumped docker/setup-buildx-action (v4.3.0 → v4.4.0) and docker/build-push-action (v7.3.0 → v7.4.0) in .github/aw/actions-lock.json, but the wasm golden fixture for smoke-copilot.md was never regenerated, so the compiler's current output (using the new pins) no longer matched the golden snapshot.

Stale wasm golden fixture

  • Type: Pre-flight repair (test correctness, not test suppression)
  • Impact: Unblocks test-unit in CI for every future run/PR on main
  • Risk: Very low — golden file only, no production code changed
  • Changes: Regenerated pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden via make update-wasm-golden, updating only the two docker action pin lines to match the current actions-lock.json
  • Rationale: Golden files must track the current action-pin lock file; this is a one-line drift issue introduced by the automated actions-version-bump workflow, not a real behavior regression

Expected Impact

Restores test-unit to green, unblocking CI signal for all subsequent PRs and pushes to main.

Validation Results

  • go test ./pkg/workflow/... -run 'TestWasmGolden' → all golden tests PASS
  • Confirmed the 5 other pkg/workflow test failures observed (TestCloudHypervisorSetupBundleScriptExecutesAgainstFixtures, TestBuildDynamicEnclaveExpiryScriptResolvesMinOfConfiguredAndJobExpiry, TestGitPatchFromHEADCommits, TestMaskOTLPHeadersScript, TestMaskOTLPAttributesScript) are pre-existing sandbox-environment issues (missing /dev/fd/N process-substitution support) unrelated to this change — reproduced identically with the fix stashed out.
  • No production code was modified; change is scoped to a single golden testdata file.

Metrics Baseline

  • Before: test-unit exit code 1 (wasm golden mismatch)
  • After: TestWasmGolden_CompileFixtures suite passes cleanly

Warning

Firewall blocked 3 domains

The following domains were blocked by the firewall during workflow execution:

  • github.com/ghapi
  • github.com
  • github.com/ghraw

[!TIP]
github.com/ghapi is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding github.com/ghapi to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to github.com/ghapi:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com/ghapi"
    - "github.com"
    - "github.com/ghraw"

See Network Configuration for more information.

Generated by CI Optimization Coach · copilot · auto · 155.5 AIC · ⌖ 13.6 AIC · ⊞ 17K · ◷

  • expires on Sep 18, 2026, 6:03 AM UTC-08:00

The recent actions-update PR (#61303) bumped docker/setup-buildx-action
to v4.4.0 and docker/build-push-action to v7.4.0, but the wasm golden
test fixture for smoke-copilot.md was not regenerated, causing
TestWasmGolden_CompileFixtures/smoke-copilot to fail in CI.

Regenerated the golden file with 'make update-wasm-golden' so it
reflects the current pinned action versions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pelikhan
pelikhan marked this pull request as ready for review September 16, 2026 15:08
Copilot AI balanced review requested due to automatic review settings September 16, 2026 15:08
@pelikhan
pelikhan merged commit 038128d into main Sep 16, 2026
@pelikhan
pelikhan deleted the fix/wasm-golden-docker-action-pins-4fc920ddfc8095ae branch September 16, 2026 15:08
@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Ponytail Reviewer completed successfully!

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • ab.chatgpt.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"

See Network Configuration for more information.

Generated by Ponytail Reviewer for #61359

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor Author

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ PR Code Quality Reviewer failed during code quality review.

Warning

Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding.

What happened

The threat detection engine failed to produce results.

Review the workflow run logs for details.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor Author

✅ Test Quality Sentinel completed test quality analysis.

No test files were added or modified in this PR. Test Quality Sentinel skipped.

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Security scanning failed for Design Decision Gate 🏗️. Review the logs for details.

No ADR enforcement needed: PR does not have the 'implementation' label and has <=100 new lines of code in business logic directories.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

No applicable skill findings — this PR only regenerates a single wasm golden testdata fixture (smoke-copilot.golden) to re-sync two Docker action SHA pins with the already-updated .github/aw/actions-lock.json. Verified both new SHAs (docker/setup-buildx-action@594f3bf4... v4.4.0, docker/build-push-action@c3c9e263... v7.4.0) match the lock file exactly.

📋 Why no skills apply
  • No production code changed (generated golden fixture only)
  • No new abstractions, tests, or design surface to evaluate against /tdd, /codebase-design, /improve-codebase-architecture, or /grill-with-docs
  • /diagnosing-bugs doesn't apply — this is fixture drift correction, not a bug fix requiring a regression test
  • Change is minimal, low-risk, and mechanically verifiable (diff matches lock file 1:1)

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 16.7 AIC · ⌖ 14.9 AIC · ⊞ 10.4K
Comment /matt to run again

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The scoped golden-file updates match the verified action tags and embedded pin data.

Pull request overview

Updates the WASM golden fixture to match current Docker action pins and restore unit-test correctness.

Changes:

  • Updates Buildx to v4.4.0.
  • Updates Build Push to v7.4.0.
File summaries
File Description
pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden Aligns expected compiler output with current action pins.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Balanced

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor Author

🎉 This pull request is included in a new release.

Release: v0.89.17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants