[ci-coach] Fix stale docker action pins in wasm golden test fixture - #61359
Conversation
The recent actions-update PR (#61303) bumped docker/setup-buildx-action to v4.4.0 and docker/build-push-action to v7.4.0, but the wasm golden test fixture for smoke-copilot.md was not regenerated, causing TestWasmGolden_CompileFixtures/smoke-copilot to fail in CI. Regenerated the golden file with 'make update-wasm-golden' so it reflects the current pinned action versions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
✅ Ponytail Reviewer completed successfully! Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"See Network Configuration for more information.
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅
|
|
Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
|
✅ Test Quality Sentinel completed test quality analysis. No test files were added or modified in this PR. Test Quality Sentinel skipped.
|
|
No ADR enforcement needed: PR does not have the 'implementation' label and has <=100 new lines of code in business logic directories.
|
There was a problem hiding this comment.
Skills-Based Review 🧠
No applicable skill findings — this PR only regenerates a single wasm golden testdata fixture (smoke-copilot.golden) to re-sync two Docker action SHA pins with the already-updated .github/aw/actions-lock.json. Verified both new SHAs (docker/setup-buildx-action@594f3bf4... v4.4.0, docker/build-push-action@c3c9e263... v7.4.0) match the lock file exactly.
📋 Why no skills apply
- No production code changed (generated golden fixture only)
- No new abstractions, tests, or design surface to evaluate against
/tdd,/codebase-design,/improve-codebase-architecture, or/grill-with-docs /diagnosing-bugsdoesn't apply — this is fixture drift correction, not a bug fix requiring a regression test- Change is minimal, low-risk, and mechanically verifiable (diff matches lock file 1:1)
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 16.7 AIC · ⌖ 14.9 AIC · ⊞ 10.4K
Comment /matt to run again
There was a problem hiding this comment.
🟢 Approval recommended
The scoped golden-file updates match the verified action tags and embedded pin data.
Pull request overview
Updates the WASM golden fixture to match current Docker action pins and restore unit-test correctness.
Changes:
- Updates Buildx to v4.4.0.
- Updates Build Push to v7.4.0.
File summaries
| File | Description |
|---|---|
pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden |
Aligns expected compiler output with current action pins. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
🎉 This pull request is included in a new release. Release: |
CI Optimization Proposal — Pre-flight Repair
Summary
test-unitpre-flight validation was failing with exit code 1. Root cause:TestWasmGolden_CompileFixtures/smoke-copilotinpkg/workflowwas comparing against a stale golden file. The recent actions-update PR (#61303) bumpeddocker/setup-buildx-action(v4.3.0 → v4.4.0) anddocker/build-push-action(v7.3.0 → v7.4.0) in.github/aw/actions-lock.json, but the wasm golden fixture forsmoke-copilot.mdwas never regenerated, so the compiler's current output (using the new pins) no longer matched the golden snapshot.Stale wasm golden fixture
test-unitin CI for every future run/PR onmainpkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.goldenviamake update-wasm-golden, updating only the two docker action pin lines to match the currentactions-lock.jsonExpected Impact
Restores
test-unitto green, unblocking CI signal for all subsequent PRs and pushes tomain.Validation Results
go test ./pkg/workflow/... -run 'TestWasmGolden'→ all golden tests PASSpkg/workflowtest failures observed (TestCloudHypervisorSetupBundleScriptExecutesAgainstFixtures,TestBuildDynamicEnclaveExpiryScriptResolvesMinOfConfiguredAndJobExpiry,TestGitPatchFromHEADCommits,TestMaskOTLPHeadersScript,TestMaskOTLPAttributesScript) are pre-existing sandbox-environment issues (missing/dev/fd/Nprocess-substitution support) unrelated to this change — reproduced identically with the fix stashed out.Metrics Baseline
test-unitexit code 1 (wasm golden mismatch)TestWasmGolden_CompileFixturessuite passes cleanlyWarning
Firewall blocked 3 domains
The following domains were blocked by the firewall during workflow execution:
github.com/ghapigithub.laiyagushi.comgithub.laiyagushi.com/ghraw[!TIP]
github.com/ghapiis blocked because GitHub API access uses the built-in GitHub tools by default. Instead of addinggithub.laiyagushi.com/ghapitonetwork.allowed, usetools.github.mode: gh-proxyfor direct pre-authenticated GitHub CLI access without requiring network access togithub.laiyagushi.com/ghapi:See GitHub Tools for more information on
gh-proxymode.To allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.