Skip to content

ci: Add support for Fedora 44 and drop Fedora 42 - use ansible-core 2.21 - #886

Closed
richm wants to merge 1 commit into
mainfrom
f44-no-f42
Closed

richm wants to merge 1 commit into
mainfrom
f44-no-f42

Conversation

@richm

@richm richm commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

It's time to test with F44 and drop F42.

Use ansible-core 2.21 for testing - this is now the latest stable version.

Deprecate podman 5 install hack in favor of official github action

Signed-off-by: Rich Megginson rmeggins@redhat.com

Summary by CodeRabbit

  • Tests

    • Updated automated test environments to support Fedora 43 and 44.
    • Added coverage for newer Ansible core versions and updated bootable container scenarios.
    • Improved Podman compatibility checks for integration testing.
  • Chores

    • Updated the testing tool dependency to version 3.20.1 across CI workflows.

It's time to test with F44 and drop F42.

Use ansible-core 2.21 for testing - this is now the latest stable version.

Deprecate podman 5 install hack in favor of official github action

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
@richm richm self-assigned this Jul 22, 2026
@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Changes

The CI workflows pin tox-lsr to 3.20.1 and update Fedora, Ansible, QEMU, container, bootc, and Podman test configurations for newer platform combinations.

CI maintenance

Layer / File(s) Summary
Update tox-lsr pins
.github/workflows/ansible-lint.yml, .github/workflows/ansible-managed-var-comment.yml, .github/workflows/ansible-test.yml, .github/workflows/python-unit-test.yml, .github/workflows/qemu-kvm-integration-tests.yml
Workflow dependency installation now uses tox-lsr 3.20.1.
Refresh QEMU and container matrices
.github/workflows/qemu-kvm-integration-tests.yml
Fedora 42 scenarios are replaced with Fedora 43 and 44 variants, including standard and bootc images for Ansible core 2.20 and 2.21. Podman 5 is conditionally installed when the existing client is older.
Refresh Testing Farm platforms
.github/workflows/tft.yml
Supported-platform detection and the test matrix now cover Fedora 43 with Ansible 2.20 and Fedora 44 with Ansible 2.21.
🚥 Pre-merge checks | ✅ 4 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description does not use the required template sections and omits the requested structured details. Rewrite the PR description with the template headings: Enhancement, Reason, Result, and Issue Tracker Tickets.
Description Format ⚠️ Warning PR description has only prose plus Signed-off-by; it omits required Enhancement/Reason/Result sections from the template. Rewrite the PR description to include Enhancement (or Feature), Reason, Result, and keep Signed-off-by; add Issue Tracker or Assisted-by only if needed.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title follows Conventional Commits and accurately summarizes the Fedora 44 and ansible-core 2.21 CI updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 Checkov (3.3.8)
.github/workflows/ansible-lint.yml

Traceback (most recent call last):
File "/usr/local/bin/checkov", line 2, in
from checkov.main import Checkov
ModuleNotFoundError: No module named 'checkov'

.github/workflows/ansible-managed-var-comment.yml

Traceback (most recent call last):
File "/usr/local/bin/checkov", line 2, in
from checkov.main import Checkov
ModuleNotFoundError: No module named 'checkov'

.github/workflows/ansible-test.yml

Traceback (most recent call last):
File "/usr/local/bin/checkov", line 2, in
from checkov.main import Checkov
ModuleNotFoundError: No module named 'checkov'

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/qemu-kvm-integration-tests.yml:
- Line 114: Update the tox-lsr dependency reference in the workflow’s pip3
install command to use an existing tag or branch in the richm/tox-lsr
repository, ensuring the integration test setup resolves successfully.
- Around line 129-131: Update the “Ensure use of podman 5” step to replace the
mutable redhat-actions/podman-install@main reference with a full-length
immutable commit SHA, optionally retaining a comment identifying the pinned
version.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 16be8316-5676-4980-80e2-349a9fba2fd0

📥 Commits

Reviewing files that changed from the base of the PR and between 9f66db2 and 4929d5d.

📒 Files selected for processing (6)
  • .github/workflows/ansible-lint.yml
  • .github/workflows/ansible-managed-var-comment.yml
  • .github/workflows/ansible-test.yml
  • .github/workflows/python-unit-test.yml
  • .github/workflows/qemu-kvm-integration-tests.yml
  • .github/workflows/tft.yml

sudo apt update
sudo apt install -y --no-install-recommends git ansible-core genisoimage qemu-system-x86
pip3 install "git+https://github.com/linux-system-roles/tox-lsr@3.20.0"
pip3 install "git+https://github.com/richm/tox-lsr@3.20.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo=https://github.com/richm/tox-lsr.git
found=0

for ref in refs/tags/3.20.1 refs/heads/3.20.1; do
  if git ls-remote --exit-code "$repo" "$ref" >/dev/null; then
    echo "Found $ref"
    found=1
  fi
done

test "$found" -eq 1

Repository: linux-system-roles/network

Length of output: 164


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== workflow location =="
grep -n "tox-lsr@3.20.1" .github/workflows/qemu-kvm-integration-tests.yml || true

echo "== tox-lsr refs =="
git ls-remote https://github.com/richm/tox-lsr.git | sed -n '1,80p' | grep -E '3\.20\.1|refs/tags|refs/heads' || true

echo "== nearby workflow context =="
sed -n '100,125p' .github/workflows/qemu-kvm-integration-tests.yml

Repository: linux-system-roles/network

Length of output: 1820


🌐 Web query:

GitHub richm tox-lsr 3.20.1 tag

💡 Result:

There is no release or tag for tox-lsr version 3.20.1 in the linux-system-roles/tox-lsr repository as of July 22, 2026 [1]. The most recent recorded version in the repository is 3.19.0, which was released on May 20, 2026 [2].

Citations:


Pin tox-lsr to an existing ref.

@3.20.1 does not resolve to a tag or branch in github.com/richm/tox-lsr, so the workflow’s dependency install step will fail before the integration tests run. Use an existing ref or create/push the intended ref before merging.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/qemu-kvm-integration-tests.yml at line 114, Update the
tox-lsr dependency reference in the workflow’s pip3 install command to use an
existing tag or branch in the richm/tox-lsr repository, ensuring the integration
test setup resolves successfully.

Comment on lines +129 to +131
- name: Ensure use of podman 5
if: steps.check_platform.outputs.supported && steps.check_podman_version.outputs.need_podman_update == 1
uses: redhat-actions/podman-install@main

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== workflow excerpt =="
sed -n '110,140p' .github/workflows/qemu-kvm-integration-tests.yml || true

echo
echo "== all uses references with branch/tag refs in workflow =="
rg -n 'uses:\s*[^#]+@[A-Za-z0-9._-]+' .github/workflows/qemu-kvm-integration-tests.yml || true

echo
echo "== podman-install references in all workflows =="
rg -n 'redhat-actions/podman-install' .github/workflows || true

Repository: linux-system-roles/network

Length of output: 2010


🌐 Web query:

Github Actions security review pin actions to immutable full length commit SHA

💡 Result:

Pinning GitHub Actions to an immutable full-length (40-character) commit SHA is a recommended security best practice to prevent supply-chain attacks [1][2][3]. Because version tags (e.g., @v4) and branch references (e.g., @main) are mutable, they can be re-pointed by attackers to malicious code if an action repository is compromised [4][2]. Pinning to a specific commit SHA ensures that your workflow consistently runs the exact, audited version of the code, mitigating the risk of unauthorized changes [1][5]. To implement this practice effectively while maintaining maintainability: 1. Use the full 40-character commit SHA: Reference actions using the format owner/repo@<full-sha> [1][5]. 2. Include a trailing version comment: To ensure that automated tools like Dependabot and Renovate can still track and suggest updates, include the human-readable version as a comment on the same line [4][5]. For example: uses: actions/checkout@1d96e77 # v4.2.0 [5] 3. Enforce via policy: Administrators can enforce SHA pinning at the organization or repository level through GitHub Actions policies [1][6]. When enabled, workflows will fail if they attempt to use actions that are not pinned to a full commit SHA [6]. 4. Automate maintenance: Configure Dependabot (using the github-actions package ecosystem) to automatically manage these dependencies; it is designed to recognize and update both the SHA and the associated version comment simultaneously [4][5]. This approach provides a secure, immutable foundation for your workflows while allowing for manageable, auditable updates over time [4][5].

Citations:


Pin the Podman action to an immutable SHA.

redhat-actions/podman-install@main is a mutable branch reference, so the action code can change without a workflow review. Use a full-length commit SHA (for example with a version comment) instead.

Suggested fix
-        uses: redhat-actions/podman-install@main
+        uses: redhat-actions/podman-install@<verified-40-character-commit-sha>
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/qemu-kvm-integration-tests.yml around lines 129 - 131,
Update the “Ensure use of podman 5” step to replace the mutable
redhat-actions/podman-install@main reference with a full-length immutable commit
SHA, optionally retaining a comment identifying the pinned version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant