Repository navigation
[backport-cloud_security_posture-1.7] Sync CI configuration with main branch - #21259
Merged
Conversation
…-package v0.79.0 The CI sync (elastic#20542) replaced with_docker_compose (standalone binary installed into BIN_FOLDER) with with_docker_compose_plugin (CLI plugin installed into ~/.docker/cli-plugins). This caused elastic-package v0.79.0, which hardcodes exec.Command("docker-compose", ...), to pick up the system's docker-compose v2.24.7 (bundled with Docker 26.1.2) instead of the pinned version. Docker Compose v2.23+ changed the YAML output of `docker compose config` so that the environment field is serialized as a sequence instead of a map, which elastic-package v0.79.0 cannot unmarshal (map[string]string). Restore with_docker_compose so the pinned standalone binary is placed in BIN_FOLDER (first in PATH) and called before the system version. Call it from test_one_package.sh and test_integrations_with_serverless.sh alongside the existing plugin installation. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…TTP errors Without --fail, curl exits 0 even on 4xx responses, saving the HTML error body silently. This caused the docker-compose binary to contain an HTML page, making it fail at execution time. With --fail, HTTP errors produce a non-zero exit code so retry 5 can kick in properly. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This parameter was not available until elastic-package v0.96.0
5 tasks
Contributor
|
✅ Package owners are in sync with |
teresaromero
approved these changes
Sep 15, 2026
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved critical and moderate findings block safe approval.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This PR synchronizes CI configuration and backport tooling from main to backport-cloud_security_posture-1.7.
Changes:
- Adds Buildkite and GitHub Actions backport automation.
- Adds the standalone backport CLI and supporting scripts.
- Updates package validation, coverage tooling, dependencies, and fixtures.
The review identified unresolved critical and moderate issues in automation, synchronization, path handling, and helper scripts, along with documentation and help-command nits.
File summaries
| File | Summary |
|---|---|
tools.go |
Go tooling declarations |
go.mod |
Go module dependencies |
dev/scripts/README.md |
Developer script documentation |
dev/scripts/get_release_commit.sh |
Release commit lookup script |
dev/scripts/backport_apply.sh |
Backport application wrapper |
dev/packagenames/testdata/no_duplicates/p2/manifest.yml |
Package validation fixture |
dev/packagenames/testdata/no_duplicates/p1/manifest.yml |
Package validation fixture |
dev/packagenames/testdata/nested/no_duplicates/technology/p2/manifest.yml |
Nested package fixture |
dev/packagenames/testdata/nested/no_duplicates/technology/p1/manifest.yml |
Nested package fixture |
dev/packagenames/testdata/nested/no_duplicates/p3/manifest.yml |
Nested package fixture |
dev/packagenames/testdata/nested/duplicates/technology/p2/manifest.yml |
Duplicate package fixture |
dev/packagenames/testdata/nested/duplicates/technology/p1/manifest.yml |
Duplicate package fixture |
dev/packagenames/testdata/nested/duplicates/p3/manifest.yml |
Duplicate package fixture |
dev/packagenames/testdata/invalid_manifests/p2/manifest.yml |
Invalid manifest fixture |
dev/packagenames/testdata/invalid_manifests/p1/manifest.yml |
Invalid manifest fixture |
dev/packagenames/testdata/duplicates/p2/manifest.yml |
Duplicate package fixture |
dev/packagenames/testdata/duplicates/p1/manifest.yml |
Duplicate package fixture |
dev/packagenames/packagenames.go |
Package-name validation |
dev/packagenames/packagenames_test.go |
Package-name validation tests |
dev/import-beats/variables.go |
Import-beats variables |
dev/import-beats/variables_compact.go |
Compact variable handling |
dev/import-beats/README.md |
Import-beats documentation |
dev/import-beats/packages.go |
Import-beats package handling |
dev/import-beats/fields.go |
Import-beats field handling |
dev/import-beats/elasticsearch.go |
Elasticsearch integration |
dev/gitutil/git.go |
Git utility helpers |
dev/coverage/testdata/test-coverage-3.xml |
Coverage fixture |
dev/coverage/testdata/test-coverage-2.xml |
Coverage fixture |
dev/coverage/testdata/test-coverage-1.xml |
Coverage fixture |
dev/coverage/testdata/expected-test-coverage.xml |
Expected coverage output |
dev/coverage/coverage.go |
Coverage merging |
dev/coverage/coverage_test.go |
Coverage tests |
dev/codeowners/testdata/test_packages/package_1/manifest.yml |
CODEOWNERS fixture |
dev/codeowners/testdata/test_packages/package_1/data_stream/stream_2/.keep |
Data stream fixture |
dev/codeowners/testdata/test_packages/package_1/data_stream/stream_1/.keep |
Data stream fixture |
dev/codeowners/testdata/nested_packages/package_top/manifest.yml |
Nested package fixture |
dev/codeowners/testdata/nested_packages/category/package_nested_2/manifest.yml |
Nested package fixture |
dev/codeowners/testdata/nested_packages/category/package_nested_1/manifest.yml |
Nested package fixture |
dev/codeowners/testdata/nested_packages/category/package_nested_1/data_stream/stream_2/.keep |
Data stream fixture |
dev/codeowners/testdata/nested_packages/category/package_nested_1/data_stream/stream_1/.keep |
Data stream fixture |
dev/codeowners/testdata/devexp/manifest.yml |
CODEOWNERS fixture |
dev/codeowners/testdata/CODEOWNERS-streams-valid |
Valid CODEOWNERS fixture |
dev/codeowners/testdata/CODEOWNERS-streams-multiple-owners |
Multiple-owner fixture |
dev/codeowners/testdata/CODEOWNERS-streams-missing-owners |
Missing-owner fixture |
dev/codeowners/testdata/CODEOWNERS-owners-trailing-slash |
CODEOWNERS path fixture |
dev/codeowners/testdata/CODEOWNERS-owners-packages-datastreams |
Package/data-stream fixture |
dev/codeowners/testdata/CODEOWNERS-nested-valid |
Nested CODEOWNERS fixture |
dev/codeowners/testdata/CODEOWNERS-nested-streams-valid |
Nested stream fixture |
dev/codeowners/testdata/CODEOWNERS-nested-streams-missing-owners |
Nested missing-owner fixture |
dev/codeowners/testdata/CODEOWNERS-nested-missing-owner |
Nested owner fixture |
dev/codeowners/testdata/CODEOWNERS-nested-category-owner |
Nested category fixture |
dev/citools/subscription.go |
Subscription utilities |
dev/citools/packages.go |
Package utilities |
dev/citools/packagemanifest.go |
Package manifest utilities |
dev/citools/logsdb.go |
Logs database utilities |
dev/citools/logsdb_test.go |
Logs database tests |
dev/citools/kibana.go |
Kibana utilities |
dev/citools/kibana_test.go |
Kibana tests |
dev/citools/gomod.go |
Go module utilities |
dev/citools/gomod_test.go |
Go module tests |
cmd/backport/tools.go |
Backport CLI tooling |
cmd/backport/magefile.go |
Backport Mage targets |
cmd/backport/go.mod |
Backport module dependencies |
cmd/backport/gitutil/git.go |
Backport Git utilities |
cmd/backport/citools/packages.go |
Backport package utilities |
cmd/backport/citools/packagemanifest.go |
Backport manifest utilities |
cmd/backport/backports/packages/detect.go |
Changed-package detection |
cmd/backport/backports/owners/check.go |
Owner validation |
cmd/backport/backports/owners/check_test.go |
Owner validation tests |
cmd/backport/backports/changelog/update.go |
Changelog updates |
cmd/backport/backports/changelog/update_test.go |
Changelog update tests |
cmd/backport/backports/changelog/sync_test.go |
Changelog sync tests |
cmd/backport/backports/changelog/resolve.go |
Changelog resolution |
cmd/backport/backports/changelog/resolve_test.go |
Changelog resolution tests |
cmd/backport/backports/changelog/insert.go |
Changelog insertion |
cmd/backport/backports/changelog/insert_test.go |
Changelog insertion tests |
cmd/backport/backports/changelog/extract.go |
Changelog extraction |
cmd/backport/backports/changelog/extract_test.go |
Changelog extraction tests |
cmd/backport/backports/changelog/comment.go |
Changelog comments |
cmd/backport/.go-version |
Backport Go version |
.gitignore |
Ignore configuration |
.github/workflows/validate-yaml-dashboards.requirements.txt |
Dashboard workflow requirements |
.github/workflows/validate-package-docs.yml |
Package documentation workflow |
.github/workflows/vale-report.yml |
Vale reporting workflow |
.github/workflows/vale-lint.yml |
Vale lint workflow |
.github/workflows/updatecli/values.d/scm.yml |
Updatecli SCM configuration |
.github/workflows/updatecli/updatecli.d/sync-packages-to-bug-issue-template.yml |
Issue-template synchronization |
.github/workflows/updatecli/updatecli.d/bump-latest-9x-snapshot-version.yml |
Version update configuration |
.github/workflows/updatecli/updatecli.d/bump-latest-8x-snapshot-version.yml |
Version update configuration |
.github/workflows/updatecli/updatecli.d/bump-latest-7x-version.yml |
Version update configuration |
.github/workflows/trigger-text-auditor.yml |
Text auditor workflow |
.github/workflows/trigger-stale-issues.yml |
Stale issue workflow |
.github/workflows/trigger-pr-review.yml |
PR review workflow |
.github/workflows/trigger-pr-actions-detective.yml |
Actions detective workflow |
.github/workflows/trigger-package-tests-security-ml.yml |
Package test workflow |
.github/workflows/trigger-newbie-contributor-patrol.yml |
Contributor patrol workflow |
.github/workflows/trigger-mention-in-pr.yml |
PR mention workflow |
.github/workflows/trigger-mention-in-issue.yml |
Issue mention workflow |
.github/workflows/trigger-issue-triage.yml |
Issue triage workflow |
.github/workflows/trigger-duplicate-issue-detector.yml |
Duplicate detection workflow |
.github/workflows/trigger-docs-patrol.yml |
Documentation patrol workflow |
.github/workflows/trigger-bug-hunter.yml |
Bug hunter workflow |
.github/workflows/trigger-breaking-change-detector.yml |
Breaking-change workflow |
.github/workflows/sweep-ingest-pipeline-safety.yml |
Ingest safety workflow |
.github/workflows/sweep-field-mapping-conflicts.yml |
Field mapping workflow |
.github/workflows/sweep-dashboard-data-scope.yml |
Dashboard scope workflow |
.github/workflows/requires-update.yml |
Update requirement workflow |
.github/workflows/pr-buildkite-detective.yml |
Buildkite detective workflow |
.github/workflows/notify-package-docs-failure.yml |
Documentation failure notification |
.github/workflows/docs-preview-cleanup.yml |
Preview cleanup workflow |
.github/workflows/docs-deploy.yml |
Documentation deployment |
.github/workflows/docs-build.yml |
Documentation build |
.github/workflows/ci-comment.yml |
CI comment workflow |
.github/workflows/catalog-info.yml |
Catalog metadata workflow |
.github/workflows/bump-elastic-stack-version.yml |
Stack version updates |
.github/workflows/backport-packages-detect.yml |
Backport package detection |
.github/actions/sync-backport-changelog/action.yml |
Changelog synchronization action |
.buildkite/scripts/trigger_backport.sh |
Backport trigger script |
.buildkite/scripts/test_one_package.sh |
Single-package test script |
.buildkite/scripts/test_integrations_with_serverless.sh |
Serverless integration tests |
.buildkite/scripts/test_helpers.sh |
Buildkite test helpers |
.buildkite/scripts/test_check_backport_owners.sh |
Backport owner checks |
.buildkite/scripts/run_dev_scripts_tests.sh |
Developer script tests |
.buildkite/scripts/run_buildkite_scripts_tests.sh |
Buildkite script tests |
.buildkite/scripts/requirements-ci-python-scripts.txt |
CI Python dependencies |
.buildkite/scripts/report_issues.sh |
Issue reporting script |
.buildkite/scripts/process_benchmarks.sh |
Benchmark processing |
.buildkite/scripts/packages/security_detection_engine.sh |
Security package testing |
.buildkite/scripts/packages/crowdstrike.sh |
CrowdStrike package testing |
.buildkite/scripts/notify_backport_pr.sh |
Backport PR notifications |
.buildkite/scripts/non_package_patterns.txt |
Non-package path patterns |
.buildkite/scripts/find_oldest_supported_version.py |
Supported-version detection |
.buildkite/scripts/check_sources.sh |
Source validation |
.buildkite/scripts/check_changelog_versions_in_main.sh |
Changelog version checks |
.buildkite/scripts/check_backports_inventory.sh |
Backport inventory checks |
.buildkite/scripts/check_backport_tool.sh |
Backport tool checks |
.buildkite/scripts/build_packages.sh |
Package builds |
.buildkite/scripts/backport_branch_lib.sh |
Backport branch helpers |
.buildkite/pull-requests.json |
Pull request configuration |
.buildkite/pipeline.serverless.yml |
Serverless pipeline |
.buildkite/pipeline.schedule-weekly.yml |
Weekly scheduled pipeline |
.buildkite/pipeline.schedule-daily.yml |
Daily scheduled pipeline |
.buildkite/pipeline.publish.yml |
Publishing pipeline |
.buildkite/pipeline.backport.yml |
Backport pipeline |
.buildkite/pipeline.backport-dispatch.yml |
Backport dispatch pipeline |
.buildkite/hooks/pre-exit |
Buildkite exit hook |
.buildkite/hooks/post-checkout |
Buildkite checkout hook |
Review details
Suppressed comments (18)
.buildkite/pipeline.yml:168
- This makes the owner check non-blocking:
check_backport_owners.shexits 1 when it finds mismatches, butsoft_fail: truelets the Buildkite build (and therefore the backport PR) pass anyway. Since this check is intended to enforce owner synchronization on PRs targeting backport branches, remove the soft-fail setting or set it to false.
.buildkite/scripts/backport_branch.sh:172 git rm --cachedremoves only the index entry and leaves backport-only tracked files in the worktree; the followinggit add .buildkitestages those stale files again. This means the branch is not synced verbatim frommainand obsolete CI scripts can persist. Remove the tracked directory from both index and worktree before checking outmain(and apply the same change to the other directory syncs below).
.buildkite/scripts/backport_branch.sh:214- As with the
.buildkitesync above,--cachedleaves tracked files that exist only on the backport branch in the worktree, andgit add cmd/backportre-adds them. Obsolete files can therefore survive the supposed copy frommain; remove the directory from the worktree as well before checking it out.
.buildkite/scripts/backport_branch.sh:219 --cachedleaves tracked files absent frommainin the worktree, and the latergit add devstages them again. Thedev/tree can consequently retain obsolete scripts despite this sync; remove the tracked directory from the worktree before checking outmain.
.buildkite/scripts/backport_branch.sh:245--cachedleaves tracked workflows that were removed frommainin the worktree, andgit add .github/workflowsstages them back into the branch. This can preserve obsolete workflows and violates the stated verbatim sync; remove the tracked directory from the worktree before checking outmain.
.buildkite/scripts/backport_branch.sh:250--cachedleaves tracked actions absent frommainin the worktree, and the subsequentgit add .github/actionsstages them again. Obsolete actions can therefore survive this sync; remove the tracked directory from the worktree before checking outmain.
.buildkite/scripts/test_integrations_with_serverless.sh:102- This duplicates the same
grep -q/pipefailhazard in the serverless matrix: a sufficiently large changed-file list can cause SIGPIPE and silently drop the matching package. Replace both quiet greps with non-quiet greps redirected to/dev/null, as done elsewhere incommon.sh.
.buildkite/scripts/trigger_integrations_in_parallel.sh:70 - These
grep -qpipelines run withpipefail; when a large changed-file list exceeds the pipe buffer,grepcan exit after the first match andechocan receive SIGPIPE, making the condition false. That can omit an affected package from the generated test matrix. Use the existing no--qpattern (grep -E ... > /dev/null) here.
.github/workflows/auto-backport.yml:108 - The issue-comment path never verifies that the merged PR targets
main(the push path does). A marker-containing comment on a merged PR targeting another branch can therefore enter the backport processor and use that PR's merge commit as the source. IncludebaseRefNamein this query and skip unless it ismain.
.github/workflows/post-backport-checklist.yml:107 - When the last active branch disappears,
render-checklistintentionally returns an empty body, but this early exit leavesCOMMENT_IDuntouched. The old checklist can then continue to show stale checked branches and remain eligible for auto-backport processing; delete the existing comment whenCOMMENT_IDis non-empty before exiting.
.github/workflows/validate-yaml-dashboards.yml:172 - This extracts only the first path segment after
packages/. For a supported nested package such aspackages/technology/p1/_dev/shared/kibana, it compiles intopackages/technology/kibana/dashboardinstead ofpackages/technology/p1/kibana/dashboard, so valid nested-package dashboards are reported as out of sync. Derive the package root by removing/_dev/...frominput_dir.
cmd/backport/backports/apply/apply.go:703 commitOwnerSyncstagesmanifest.ymlbefore it stagesCODEOWNERSand may fail after either operation.git checkout --restores the worktree from the index, so it preserves any staged owner changes instead of restoringHEAD; a best-effort sync failure can therefore leave a partial staged change and prevent the caller from returning to a clean branch. Restore both the index and worktree fromHEAD(for example withgit restore --source=HEAD --staged --worktree -- ...).
cmd/backport/backports/apply/apply.go:943- A full branch target is accepted based only on the generic regex; it is never checked against
packageName. This allows--package aws --target backport-prometheus-6.14to resolve and apply an AWS commit onto Prometheus' backport branch. Validate full targets withbackports.ValidateBranchName(packageName, target)before returning them.
cmd/backport/backports/apply/apply.go:214 - On the successful non-dry-run path this checks out the original branch but never deletes
workingBranch, even though the cleanup comment says retries should not fail with “branch already exists” and the next comment says local presence is no longer needed. A second invocation with the same SHA in the same checkout therefore fails atcheckout -b; delete the local working branch after successfully restoring the original branch.
cmd/backport/backports/packages/detect.go:35 - The changed paths passed by
git diff --name-onlyuse/, whilefilepath.Separatoris\on Windows andListPackagesWithNamesreturns OS-native paths. On Windows this makes everystrings.HasPrefixcheck fail, sodetect-packagesandcheck-ownerscan silently report no packages; normalize both sides withfilepath.ToSlashbefore comparing.
cmd/backport/main.go:51 - The documented order allows
backport check-active <branch> --json, but Go'sflag.FlagSetstops parsing when it reaches<branch>, so--jsonis treated as an extra positional argument and JSON output is silently disabled. Document the supported flag-before-argument order (or use a parser that accepts both orders).
cmd/backport/main.go:56 - The usage text places
--jsonafter the positional arguments, butrunDetectPackagesuses Go'sflag.FlagSet, which stops parsing at the first positional argument. Following this documented form therefore emits plain output instead of JSON; show the supported flag-before-argument order (or change parsing to accept both).
dev/scripts/backport_apply.sh:53 usage()always exits 1, so-h|--helpreports failure and the wrapper's help command cannot succeed. Pass an explicit zero status for the help case (while retaining status 1 for invalid/missing arguments).
- Files reviewed: 174/193 changed files
- Comments generated: 5
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| PR_AUTHOR: ${{ steps.resolve.outputs.pr_author }} | ||
| COMMENT_ID: ${{ steps.find-comment.outputs.comment_id }} | ||
| BODY_FILE: ${{ steps.find-comment.outputs.body_file }} | ||
| run: .github/scripts/backport/process-checked-branches.sh |
| } | ||
|
|
||
| // branchRE matches valid backport branch names (mirrors cmd/backport/backports/inventory.go). | ||
| var branchRE = regexp.MustCompile(`^backport-[a-zA-Z0-9_]+-[0-9][0-9.]*x?$`) |
Comment on lines
+157
to
+160
| if echo "${stripped}" | grep -qE '^.+-[0-9]+\.[0-9]+(\.[0-9]+)?$'; then | ||
| pkg="$(echo "${stripped}" | sed -E 's/-([0-9]+\.[0-9]+(\.[0-9]+)?)$//')" | ||
| ver_suffix="$(echo "${stripped}" | sed -E 's/^.*-([0-9]+\.[0-9]+(\.[0-9]+)?)$/\1/')" | ||
| fi |
Comment on lines
+7
to
+22
| usage() { | ||
| echo "Usage: $0 -p <package_name> -v <version>" >&2 | ||
| exit 1 | ||
| } | ||
|
|
||
| PACKAGE_NAME="" | ||
| VERSION="" | ||
|
|
||
| while getopts ":p:v:h" opt; do | ||
| case "${opt}" in | ||
| p) PACKAGE_NAME="${OPTARG}" ;; | ||
| v) VERSION="${OPTARG}" ;; | ||
| h) | ||
| usage | ||
| exit 0 | ||
| ;; |
| @@ -0,0 +1,85 @@ | |||
| #!/usr/bin/env bash | |||
| # Finds the commit on main where a package version was released. | |||
| # Usage: ./get_release_commit.sh <package_name> <version> | |||
mrodm
merged commit Sep 15, 2026
5418dd4
into
elastic:backport-cloud_security_posture-1.7
9 of 10 checks passed
Contributor
|
Changelog sync skipped — all changelog versions are already present on |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
Syncs
.buildkiteand.githubCI configuration frommainto thebackport-cloud_security_posture-1.7backport branch.This brings automated backport workflows, new CI scripts, Go tooling, and
GitHub Actions that only work when they are present on the target branch itself.
It also includes several follow-up fixes discovered after the initial sync.
Proposed commit message
```
Sync CI configuration with main branch for backport-cloud_security_posture-1.7.
Keep CI pipelines, GitHub Actions, and tooling consistent between active backport
branches and `main`, so that automated backport workflows and tooling improvements
land on all supported branches.
WHY:
GitHub Actions resolves workflow files from the branch where the event occurs,
not from `main`. Backport-branch workflows (changelog sync, post-backport
checklist, owner checks, auto-backport) must be present on the backport branch
itself to fire correctly.
Additional fixes included in this sync:
```
Author's Checklist
How to test this PR locally
N/A — CI-only changes. Validate by confirming GitHub Actions workflows trigger
correctly on the `backport-cloud_security_posture-1.7` branch after merge.
Related issues
🤖 Generated with Claude Code