- Pin the permit-opa checkout in tests.yml and release.yml to a commit
(ab54a37, today's permit-opa main) instead of `ref: main`; tests.yml checks
the two pins agree. release.yml's checkout moves to v4.
- opa_build: OPA_BUILD now picks the binary as well as the plugin config
(permit requires the tarball; vanilla downloads a pinned OPA 1.20.2 with
--fail and a sha256 check); runs on $BUILDPLATFORM and cross-compiles for
$TARGETARCH; drops `-a` so the go-build cache mount works.
- tests.yml builds opa_build for linux/arm64 on every run.
- build_opal_bundle.sh: set -euo pipefail, always clears custom/; the two
workflow tar steps run under shell: bash (pipefail).
- test_offline_mode: python:3.13-alpine3.23 instead of python:alpine.
- Dockerfile prose: no PR heads/status, describes the pin; VEX removal
gates follow the pin.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Follow-ups from Zeev's 2026-09-23 review of #342 (merged). #342 left 9 findings open: 5 inline threads and 4 in the review body. This PR fixes all 9.
Findings and changes
Pin the permit-opa checkout (body, MEDIUM, tests.yml:52 / release.yml:43)
ab54a3766111b3f6c4796c5ab0a7d7e75f7f590d(permit-opa main today, [Snyk] Security upgrade aiohttp from 3.7.2 to 3.8.0 #51) instead ofref: main, so the shipped/app/bin/opadoesn't change unless a PDP commit changes it.actions/checkout@v3to@v4.No CI gate for arm64 opa_build (body, MEDIUM, tests.yml:77)
--target opa_build --platform linux/arm64. That stage now cross-compiles (see below), so the extra build is cheap.OPA_BUILD picks the plugin, not the binary (thread, MEDIUM, Dockerfile:166)
ARG OPA_BUILD:permitneedscustom/custom_opa.tar.gzand fails with a clear message if it's missing.vanilladownloads upstream OPA.PDP_OPA_PLUGINS.custom/. WithPDP_VANILLA=trueit tells you to pass--build-arg OPA_BUILD=vanilla.Vanilla fallback:
latest, no --fail, no checksum (thread, LOW, Dockerfile:175)OPA_VERSION(1.20.2, today'slatest) withcurl --fail --show-error, checks it against a hardcoded sha256 for each arch, and picks the arch from$TARGETARCH, notuname -m.-adefeats the build cache; opa_build under QEMU (thread, LOW, Dockerfile:175)-a. The stage is nowFROM --platform=$BUILDPLATFORMand cross-compiles withGOOS=linux GOARCH=$TARGETARCH, so the arm64 release leg no longer compiles under QEMU.go.mod go 1.26.0; PDP opa_build: golang:1.26 - ok).PDP#338 note describes an old #338 head (thread, LOW, Dockerfile:97)
"Both are open" (thread, LOW, Dockerfile:109)
ref: mainbackport rule are replaced by a short description of the pin. They also say that a release cut from a commit before the pin (v0.9.15 and older) still takes permit-opa main.build_opal_bundle.sh masks a failing find (body, LOW)
set -euo pipefailand${PDP_VANILLA:-}.Pre buildsteps now useshell: bash, which runs with pipefail.test_offline_mode base has no version (body, LOW)
FROM python:3.13-alpine3.23, matching the main image. Adding a digest waits for ci: gate releases on CVEs and unify Dependabot, Trivy and Docker Scout (PER-15358) #338's convention.Validation (local, Docker Desktop on arm64)
docker buildx build --target opa_build, using a permit-opa tarball built exactly like tests.yml builds it (find * ... | xargs -0 tar):linux/arm64(native) andlinux/amd64(cross-compiled on the arm64 host): both build.go version -m /opashows go1.26.8,CGO_ENABLED=0,-tags=netgo, and the rightGOARCH. The ELF machine bytes are aarch64 and x86-64.go 1.26.0), arm64: builds, with x/crypto v0.57.0.OPA_BUILD=vanillaon both arches: builds, and the checksums match./opa: FAILED). A missing version fails (curl: (22) ... 404).OPA_BUILD=permitwith no tarball fails with the message.OPA_BUILD=bogusfails.docker buildx build --check .: the same single pre-existing warning as main.actionlint: nothing new. Its remaining findings (SC2035 on the tar line, and the Docker Hub secrets in docker-scout) are also on main.shellcheck build_opal_bundle.sh: only the same SC2035 info.pre-commit run --files ...: pass.find: *: No such file, rc=1) instead of producing a tarball. A vanilla run leavescustom/empty.Merge order / notes
go 1.25.0) until a PDP PR moves it past [Snyk] Security upgrade aiohttp from 3.7.2 to 3.8.0 #52.pdp-buildercheck (added in permit-opa#52) no longer guards a floating build. Its own comment says to delete it and the workflow when the PDP stops usingref: main. That is a permit-opa change for after this merges.🤖 Generated with Claude Code