Skip to content

ci: exclude the PIP detector from the Blossom scan - #1056

Merged
podkidyshev merged 1 commit into
NVIDIA:mainfrom
orbalayla-nvidia:ci/blackduck-exclude-pip
Sep 23, 2026
Merged

podkidyshev merged 1 commit into
NVIDIA:mainfrom
orbalayla-nvidia:ci/blackduck-exclude-pip

Conversation

@orbalayla-nvidia

Copy link
Copy Markdown
Contributor

The Vulnerability scan stage fails on every pull request:

pyenv: version `3.14' is not installed (set by /src/.python-version)

Detect invokes python for its PIP detector, so pyenv reads the repo's .python-version and asks for a version the scanner image does not have. It exits before scanning anything, which then skips Start ci job — so the Jenkins job has never run from a pull request.

Excluding the PIP detector stops Detect invoking python at all. Confirmed by Blossom as a supported workaround, and NVFlare runs the same configuration.

PIP only, matching NVFlare — this repo has no poetry.lock or environment.yml, so the POETRY and CONDA detectors would not fire regardless.

Trade-off

This scan no longer detects Python dependencies. That coverage is not lost overall: the release pipeline installs the package into its own environment and runs the full Black Duck scan there. Blossom are working on pinning the scanner's own interpreter, at which point this line can be removed.

Detect invokes python for the PIP detector, so pyenv reads the repo
.python-version and fails on 3.14, which the scanner image does not have.
Every pull request fails before anything is scanned.

Workaround until Blossom pins the scanner interpreter. The release
pipeline still scans Python dependencies with its own environment.

Refs: HPCINFRA-4854
Signed-off-by: Or Balayla <obalayla@nvidia.com>
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: NVIDIA/cloudai/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: eddc9be0-5c5f-48e5-a0bf-e3f08e412f65

📥 Commits

Reviewing files that changed from the base of the PR and between c87a895 and 63c5e91.

📒 Files selected for processing (1)
  • .github/workflows/blossom-ci.yml

Included review availability: Your plan provides up to 12 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The vulnerability-scan job writes a property that excludes the PIP detector from the Blossom scan. Comments describe a Python version issue and separate Python dependency scanning in the release pipeline.

Changes

Blossom vulnerability scan

Layer / File(s) Summary
Configure detector exclusion
.github/workflows/blossom-ci.yml
The job writes detect.excluded.detector.types=PIP. Comments describe the Python version issue with the detector and note that the release pipeline scans Python dependencies separately.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 63c5e

The change should let pull-request jobs proceed past the Python-version failure. Release-scan coverage could not be confirmed from this repository, but no actionable defect was established that would prevent merging.

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: excluding the PIP detector from the Blossom scan.
Description check ✅ Passed The description explains the scan failure, the PIP detector exclusion, and the effect on Python dependency coverage. It matches the changeset.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@podkidyshev
podkidyshev merged commit 1517610 into NVIDIA:main Sep 23, 2026
8 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants