Skip to content

ci: install bubblewrap before the release workflow's tests - #71

Merged
radim10 merged 1 commit into
masterfrom
ci/release-install-bubblewrap
Oct 9, 2026
Merged

radim10 merged 1 commit into
masterfrom
ci/release-install-bubblewrap

Conversation

@radim10

@radim10 radim10 commented Oct 9, 2026

Copy link
Copy Markdown
Member

Problem

The v0.20.0 release run (run 37942358328) failed in Verify CLI, so no binaries were built and nothing was published:

scan confinement must run in CI: secret_scan needs bubblewrap (`bwrap`) on Linux to confine the host-side scan
test result: FAILED. 583 passed; 3 failed

#68 made the secret-scan confinement tests fail rather than skip in CI when bubblewrap is missing, and added an install step to ci.yaml. The release workflow runs its own cargo test in a separate verify job, which never got that step.

Change

Adds the same Install bubblewrap step (bubblewrap, apparmor-profiles, the bwrap-userns-restrict profile) to the release workflow's verify job, before cargo test. The job always runs on ubuntu-latest, so it needs no OS condition.

Verification

PR CI doesn't run release.yaml. The step is copied verbatim from ci.yaml, where it makes the same three tests pass on ubuntu-latest. The real check is re-running the release for v0.20.0 after merge.

The secret-scan confinement tests (#68) fail rather than skip in CI
without bubblewrap. ci.yaml installs it, but the release workflow's
verify job didn't, so the v0.20.0 release run failed before building.
@radim10 radim10 self-assigned this Oct 9, 2026
@radim10
radim10 merged commit dae4c47 into master Oct 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant