Repository navigation
ci: install bubblewrap before the release workflow's tests - #71
Merged
Merged
Conversation
The secret-scan confinement tests (#68) fail rather than skip in CI without bubblewrap. ci.yaml installs it, but the release workflow's verify job didn't, so the v0.20.0 release run failed before building.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The v0.20.0 release run (run 37942358328) failed in Verify CLI, so no binaries were built and nothing was published:
#68 made the secret-scan confinement tests fail rather than skip in CI when bubblewrap is missing, and added an install step to
ci.yaml. The release workflow runs its owncargo testin a separate verify job, which never got that step.Change
Adds the same Install bubblewrap step (bubblewrap,
apparmor-profiles, thebwrap-userns-restrictprofile) to the release workflow's verify job, beforecargo test. The job always runs onubuntu-latest, so it needs no OS condition.Verification
PR CI doesn't run
release.yaml. The step is copied verbatim fromci.yaml, where it makes the same three tests pass onubuntu-latest. The real check is re-running the release for v0.20.0 after merge.