ci: exclude the PIP detector from the Blossom scan - #1056
Conversation
Detect invokes python for the PIP detector, so pyenv reads the repo .python-version and fails on 3.14, which the scanner image does not have. Every pull request fails before anything is scanned. Workaround until Blossom pins the scanner interpreter. The release pipeline still scans Python dependencies with its own environment. Refs: HPCINFRA-4854 Signed-off-by: Or Balayla <obalayla@nvidia.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: NVIDIA/cloudai/.coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 12 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe vulnerability-scan job writes a property that excludes the PIP detector from the Blossom scan. Comments describe a Python version issue and separate Python dependency scanning in the release pipeline. ChangesBlossom vulnerability scan
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The change should let pull-request jobs proceed past the Python-version failure. Release-scan coverage could not be confirmed from this repository, but no actionable defect was established that would prevent merging. 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1🧪 Generate unit tests (beta)
🛠️ Fix failing CI checks 💡
Comment |
The Vulnerability scan stage fails on every pull request:
Detect invokes python for its PIP detector, so pyenv reads the repo's
.python-versionand asks for a version the scanner image does not have. It exits before scanning anything, which then skipsStart ci job— so the Jenkins job has never run from a pull request.Excluding the PIP detector stops Detect invoking python at all. Confirmed by Blossom as a supported workaround, and NVFlare runs the same configuration.
PIPonly, matching NVFlare — this repo has nopoetry.lockorenvironment.yml, so the POETRY and CONDA detectors would not fire regardless.Trade-off
This scan no longer detects Python dependencies. That coverage is not lost overall: the release pipeline installs the package into its own environment and runs the full Black Duck scan there. Blossom are working on pinning the scanner's own interpreter, at which point this line can be removed.