Skip to content

Use compatible local zizmor and poutine scanners when available - #66918

Merged
pelikhan merged 4 commits into
mainfrom
copilot/add-support-for-zizmor-poutine
Oct 8, 2026
Merged

pelikhan merged 4 commits into
mainfrom
copilot/add-support-for-zizmor-poutine

Conversation

Copilot AI commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Compilation currently requires Docker for zizmor and poutine even when the scanners are installed locally. This change checks local versions automatically and retains the pinned Docker images as fallback.

  • Scanner selection: Use local zizmor ≥ 1.30.1 or poutine ≥ 1.1.6. Fall back to Docker when a binary is missing, too old, or has an unreadable version.
  • MCP compilation: Skip Docker image preparation for eligible local scanners without changing the requirements of other Docker-based checks.
  • Coverage and docs: Add version-selection and fallback tests, and document the minimum versions.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI requested a review from pelikhan October 8, 2026 14:52
@pelikhan
pelikhan marked this pull request as ready for review October 8, 2026 19:01
Copilot AI balanced review requested due to automatic review settings October 8, 2026 19:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Poutine detection uses an unsupported flag, and scanner tests have host-dependent PATH and symlink assumptions.

4 open findings
What changed in this PR

This PR adds local-scanner selection to gh-aw compilation while retaining pinned Docker fallbacks.

Changes:

  • Prefer local zizmor ≥ 1.30.1 and poutine ≥ 1.1.6.
  • Adjust MCP Docker preparation and add selection tests and documentation.
  • Refresh generated workflow schemas to allow null milestones.
File Description
pkg/​cli/​zizmor.go Select local zizmor before Docker.
pkg/​cli/​scanner_local.go Detect compatible scanner versions.
pkg/​cli/​scanner_local_test.go Test selection and Docker fallback.
pkg/​cli/​poutine.go Share local-or-Docker command construction.
pkg/​cli/​mcp_tools_readonly.go Preserve local scanners without Docker.
pkg/​cli/​docker_images.go Skip images for compatible local scanners.
docs/​src/​content/​docs/​setup/​cli.md Document minimum versions and fallback.
.github/​workflows/​workflow-health-manager.lock.yml Allow null milestones.
.github/​workflows/​workflow-generator.lock.yml Allow null milestones.
.github/​workflows/​sub-issue-closer.lock.yml Allow null milestones.
.github/​workflows/​smoke-ci.lock.yml Allow null milestones.
.github/​workflows/​pr-sous-chef.lock.yml Allow null milestones.
.github/​workflows/​poem-bot.lock.yml Allow null milestones.
.github/​workflows/​lint-monster.lock.yml Allow null milestones.
.github/​workflows/​eslint-monster.lock.yml Allow null milestones.
.github/​workflows/​daily-squid-image-scan.lock.yml Allow null milestones.
.github/​workflows/​bot-detection.lock.yml Allow null milestones.
.github/​workflows/​aw-failure-investigator.lock.yml Allow null milestones.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/cli/docker_images.go
Comment on lines +270 to +271
if opts.Zizmor && localScannerPath(ctxutil.OrBackground(ctx), "zizmor") != "" {
opts.Zizmor = false

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added an isolated PATH to Docker-fallback tests that request zizmor or poutine, preventing host-installed scanners from bypassing the Docker mocks. Commit: 6270c641.

Comment thread pkg/cli/scanner_local.go Outdated
if err := os.Remove(poutine); err != nil {
t.Fatal(err)
}
cmd, args, err = buildPoutineCommand(root)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The fallback assertion now temporarily restricts PATH to the fixture directory, then restores the original PATH before the test continues. Commit: 6270c641.

Comment thread pkg/cli/scanner_local_test.go Outdated
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/cli/docker_images.go:271): The existing Docker-preparation tests mock Docker but leave scanner discovery on the host PATH. With compatible zizmor installed, this branch clears the only requested tool and returns nil before consulting those mocks. For example, TestCheckAndPrepareDockerImages_ImageAlreadyDownloading and TestCheckAndPrepareDockerImages_DockerUnavailable then fail their expected-error assertions. Give the Docker-fallback tests a controlled PATH without compatible scanners; keep the production preference for local scanners unchanged. - Use compatible local zizmor and poutine scanners when available #66918 (comment)
  3. Review (pkg/cli/scanner_local.go:40): Poutine v1.1.6 provides a version subcommand, not --version (upstream implementation). This probe exits nonzero and rejects a supported installation, so compilation still falls back to Docker or skips poutine when Docker is unavailable in MCP. Use version --disable-version-check for poutine to avoid its update check during detection. Also make the test fixture reject unsupported arguments and update the documentation's shared --version claim. - Use compatible local zizmor and poutine scanners when available #66918 (comment)
  4. Review (pkg/cli/scanner_local_test.go:91): Removing the fixture does not guarantee poutine is missing: line 71 retains the host PATH. After correcting poutine's version probe, a compatible host installation will be selected here instead of Docker, making this fallback assertion fail. Restrict PATH to the fixture directory for this call, then restore it so later git-root discovery still works. - Use compatible local zizmor and poutine scanners when available #66918 (comment)
  5. Review (pkg/cli/scanner_local_test.go:22): Return the resolved fixture path here. fileutil.ResolveExecutablePath resolves symlinks (pkg/fileutil/executable.go:25–27), while this helper returns the original spelling. If the temporary directory has a symlinked ancestor, such as /var on macOS, the eligible-scanner and command-path assertions fail even though discovery succeeds. Resolve the path before returning it so expected and actual paths use the same form. - Use compatible local zizmor and poutine scanners when available #66918 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 022f812
Sous-chef work: 131365085be9a3381ae6c3a43cccd1a2df5a5bf6c670c303f5405545aab6e148 46a9f238779870bf6ee6f616170b60667a668d8d153fedb826a73064b7507d4c 8f5a55c14e0471c7144308db0eb40f4f1c1a6430029a7f054673c8f7f8757bd8 ccc8edd77d59003b28771207920616ada15e9f67e03259068220e5ed1f5315ab
Sous-chef state: 36adae3ed8912a5ec58e726e61e04cebd3ce7290a3d34540b8a8911e41189842

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 6.3 AIC · ⌖ 7.93 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 8, 2026 19:34
…or-zizmor-poutine

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Copilot AI requested a review from gh-aw-bot October 8, 2026 19:46
@pelikhan
pelikhan merged commit 97b7009 into main Oct 8, 2026
36 checks passed
@pelikhan
pelikhan deleted the copilot/add-support-for-zizmor-poutine branch October 8, 2026 19:52
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants