Skip to content

Remove OSSM from Go stdlib builder-container auto-affects - #1472

Open
jasinner wants to merge 2 commits into
RedHatProductSecurity:masterfrom
jasinner:ace-remove-ossm-from-go-stdlib-builder
Open

jasinner wants to merge 2 commits into
RedHatProductSecurity:masterfrom
jasinner:ace-remove-ossm-from-go-stdlib-builder

Conversation

@jasinner

@jasinner jasinner commented Sep 4, 2026

Copy link
Copy Markdown

Summary

  • Remove ossm-2 and ossm-3 from GO_STDLIB_BUILDER_PRODUCTS in ACE's Go stdlib workflow
  • Stops Phase 4 from auto-creating openshift-golang-builder-container affects for OSSM streams

OSSM container images (e.g. openshift-service-mesh/kiali-rhel9) are already discovered and version-checked via the standard lib-newtopia search path. The synthetic builder-container affects were redundant for OSSM and produced duplicate/incorrect offerings (see CVE-2026-56862).

Test plan

  • pytest apps/ace/tests/test_tasks.py::test_handle_go_stdlib_phase4_creates_builder_affects still passes (uses openshift-4, unaffected by this change)
  • On a Go stdlib flaw, ACE Phase 4 still creates builder-container affects for openshift-4 and cnv-4 active streams
  • OSSM streams no longer receive synthetic openshift-golang-builder-container affects from Phase 4

Made with Cursor

Stop ACE Phase 4 from creating openshift-golang-builder-container
affects for ossm-2 and ossm-3 streams; OSSM containers are already
handled via the standard lib-newtopia search path.

Co-authored-by: Cursor <cursoragent@cursor.com>
@coderabbitai

coderabbitai Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • docs/CHANGELOG.md is excluded by !docs/CHANGELOG.md

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: e6a4d2d4-1c9c-463e-be67-4f6fe63a8f26

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Team

Run ID: 26ed75f2-498b-4c73-8d88-487e05a65a3a

📥 Commits

Reviewing files that changed from the base of the PR and between df9e7da and 89f4c8e.

📒 Files selected for processing (1)
  • apps/ace/constants.py

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (2)
  • GitHub Check: detect-secrets
  • GitHub Check: tests
⚠️ CI failures not shown inline (2)

GitHub Actions: Meta checks / 1_changelog.txt: Remove OSSM from Go stdlib builder-container auto-affects

Conclusion: failure

View job details

##[group]Run Zomzog/changelog-checker@v1.3.0
 with:
   fileName: docs/CHANGELOG.md
   noChangelogLabel: technical
   checkNotification: Simple
 env:
   GITHUB_***REDACTED_SECRET_ASSIGNMENT***
 ##[endgroup]
 (node:2243) [DEP0169] DeprecationWarning: `url.parse()` behavior is not standardized and prone to errors that have security implications. Use the WHATWG URL API instead. CVEs are not issued for `url.parse()` vulnerabilities.
 (Use `node --trace-deprecation ...` to show where the warning was created)
 docs/CHANGELOG.md must be updated
 ##[error]docs/CHANGELOG.md must be updated

GitHub Actions: Meta checks / changelog: Remove OSSM from Go stdlib builder-container auto-affects

Conclusion: failure

View job details

##[group]Run Zomzog/changelog-checker@v1.3.0
 with:
   fileName: docs/CHANGELOG.md
   noChangelogLabel: technical
   checkNotification: Simple
 env:
   GITHUB_***REDACTED_SECRET_ASSIGNMENT***
 ##[endgroup]
 (node:2243) [DEP0169] DeprecationWarning: `url.parse()` behavior is not standardized and prone to errors that have security implications. Use the WHATWG URL API instead. CVEs are not issued for `url.parse()` vulnerabilities.
 (Use `node --trace-deprecation ...` to show where the warning was created)
 docs/CHANGELOG.md must be updated
 ##[error]docs/CHANGELOG.md must be updated
🧰 Additional context used
📓 Path-based instructions (2)
Injection prevention (prodsec-skills): SQL: parameterized queries only; no string concatenation Command: no shell=True, os.system, or backtick exec with user input LDAP/XPath: escape special characters in filters Path traversal: canonicaliz...

⚙️ CodeRabbit configuration file

Files:

  • apps/ace/constants.py
Python security (prodsec-skills): No pickle.loads, marshal.load, shelve.open on untrusted data (RCE) No eval, exec, compile on non-literal input; use ast.literal_eval No yaml.load without SafeLoader; require yaml.safe_load subprocess: list...

⚙️ CodeRabbit configuration file

Files:

  • apps/ace/constants.py
🔇 Additional comments (1)
apps/ace/constants.py (1)

104-104: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated Go standard library workflows to target only the OpenShift 4 and CNV 4 builder products.

Walkthrough

The Go stdlib workflow now targets only the openshift-4 and cnv-4 builder products. The ossm-2 and ossm-3 entries were removed.

Changes

Go stdlib builder product scope

Layer / File(s) Summary
Update builder product constant
apps/ace/constants.py
GO_STDLIB_BUILDER_PRODUCTS now contains only openshift-4 and cnv-4.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to 89f4c

The Go stdlib workflow will stop creating redundant OSSM builder-container affects while retaining openshift-4 and cnv-4 handling. The scoped configuration change is ready to merge.

Suggested reviewers: dmonzonis, elkasitu

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Ai-Attribution ⚠️ Warning AI use is explicit: the PR description says it was made with Cursor, and the PR commit includes Co-authored-by: Cursor <cursoragent@cursor.com>. The commit has no Assisted-by or Generated-by tra… Amend the commit to remove the AI Co-Authored-By/Co-authored-by trailer and add a Red Hat-approved Assisted-by or Generated-by trailer identifying Cursor, then update the PR.
✅ Passed checks (10 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: removing OSSM from Go stdlib builder-container auto-affects.
Description check ✅ Passed The description directly explains the configuration change, its effect on OSSM streams, the reason for the change, and the test plan.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed PASS. The pull request changes only GO_STDLIB_BUILDER_PRODUCTS by removing ossm-2 and ossm-3. The added line contains no API key, token, password, private key, credential, embedded URL credentia…
No-Weak-Crypto ✅ Passed PASS. The PR changes only GO_STDLIB_BUILDER_PRODUCTS by removing ossm-2 and ossm-3. The exact diff introduces no MD5, SHA1, DES, 3DES, Blowfish, RC4, ECB, custom cryptography, or secret/token co…
No-Injection-Vectors ✅ Passed PASS: The pull request changes only a static Python list in apps/ace/constants.py. The diff removes ossm-2 and ossm-3; it adds no SQL concatenation, shell execution, eval/exec, `pickle.loads…
Container-Privileges ✅ Passed PASS: The pull request changes only apps/ace/constants.py, where it removes two product names from a Python list. The Phase 4 code still uses that list to select products. No container or Kubernetes…
No-Sensitive-Data-In-Logs ✅ Passed PASS: The pull request changes only the GO_STDLIB_BUILDER_PRODUCTS list. It removes two product identifiers and adds no logging statements or sensitive-data output. The affected Phase 4 logs remain …
Full details: Ai-Attribution

Explanation

AI use is explicit: the PR description says it was made with Cursor, and the PR commit includes Co-authored-by: Cursor &lt;cursoragent@cursor.com&gt;. The commit has no Assisted-by or Generated-by trailer. This fails the required Red Hat attribution and uses the prohibited Co-Authored-By form for an AI tool.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant