Conversation
It's time to test with F44 and drop F42. Use ansible-core 2.21 for testing - this is now the latest stable version. Deprecate podman 5 install hack in favor of official github action Signed-off-by: Rich Megginson <rmeggins@redhat.com>
📝 WalkthroughWalkthroughChangesThe CI workflows pin tox-lsr to 3.20.1 and update Fedora, Ansible, QEMU, container, bootc, and Podman test configurations for newer platform combinations. CI maintenance
🚥 Pre-merge checks | ✅ 4 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (4 passed)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 Checkov (3.3.8).github/workflows/ansible-lint.ymlTraceback (most recent call last): .github/workflows/ansible-managed-var-comment.ymlTraceback (most recent call last): .github/workflows/ansible-test.ymlTraceback (most recent call last):
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/qemu-kvm-integration-tests.yml:
- Line 114: Update the tox-lsr dependency reference in the workflow’s pip3
install command to use an existing tag or branch in the richm/tox-lsr
repository, ensuring the integration test setup resolves successfully.
- Around line 129-131: Update the “Ensure use of podman 5” step to replace the
mutable redhat-actions/podman-install@main reference with a full-length
immutable commit SHA, optionally retaining a comment identifying the pinned
version.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 16be8316-5676-4980-80e2-349a9fba2fd0
📒 Files selected for processing (6)
.github/workflows/ansible-lint.yml.github/workflows/ansible-managed-var-comment.yml.github/workflows/ansible-test.yml.github/workflows/python-unit-test.yml.github/workflows/qemu-kvm-integration-tests.yml.github/workflows/tft.yml
| sudo apt update | ||
| sudo apt install -y --no-install-recommends git ansible-core genisoimage qemu-system-x86 | ||
| pip3 install "git+https://github.com/linux-system-roles/tox-lsr@3.20.0" | ||
| pip3 install "git+https://github.com/richm/tox-lsr@3.20.1" |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
repo=https://github.com/richm/tox-lsr.git
found=0
for ref in refs/tags/3.20.1 refs/heads/3.20.1; do
if git ls-remote --exit-code "$repo" "$ref" >/dev/null; then
echo "Found $ref"
found=1
fi
done
test "$found" -eq 1Repository: linux-system-roles/network
Length of output: 164
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== workflow location =="
grep -n "tox-lsr@3.20.1" .github/workflows/qemu-kvm-integration-tests.yml || true
echo "== tox-lsr refs =="
git ls-remote https://github.com/richm/tox-lsr.git | sed -n '1,80p' | grep -E '3\.20\.1|refs/tags|refs/heads' || true
echo "== nearby workflow context =="
sed -n '100,125p' .github/workflows/qemu-kvm-integration-tests.ymlRepository: linux-system-roles/network
Length of output: 1820
🌐 Web query:
GitHub richm tox-lsr 3.20.1 tag
💡 Result:
There is no release or tag for tox-lsr version 3.20.1 in the linux-system-roles/tox-lsr repository as of July 22, 2026 [1]. The most recent recorded version in the repository is 3.19.0, which was released on May 20, 2026 [2].
Citations:
Pin tox-lsr to an existing ref.
@3.20.1 does not resolve to a tag or branch in github.com/richm/tox-lsr, so the workflow’s dependency install step will fail before the integration tests run. Use an existing ref or create/push the intended ref before merging.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/qemu-kvm-integration-tests.yml at line 114, Update the
tox-lsr dependency reference in the workflow’s pip3 install command to use an
existing tag or branch in the richm/tox-lsr repository, ensuring the integration
test setup resolves successfully.
| - name: Ensure use of podman 5 | ||
| if: steps.check_platform.outputs.supported && steps.check_podman_version.outputs.need_podman_update == 1 | ||
| uses: redhat-actions/podman-install@main |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "== workflow excerpt =="
sed -n '110,140p' .github/workflows/qemu-kvm-integration-tests.yml || true
echo
echo "== all uses references with branch/tag refs in workflow =="
rg -n 'uses:\s*[^#]+@[A-Za-z0-9._-]+' .github/workflows/qemu-kvm-integration-tests.yml || true
echo
echo "== podman-install references in all workflows =="
rg -n 'redhat-actions/podman-install' .github/workflows || trueRepository: linux-system-roles/network
Length of output: 2010
🌐 Web query:
Github Actions security review pin actions to immutable full length commit SHA
💡 Result:
Pinning GitHub Actions to an immutable full-length (40-character) commit SHA is a recommended security best practice to prevent supply-chain attacks [1][2][3]. Because version tags (e.g., @v4) and branch references (e.g., @main) are mutable, they can be re-pointed by attackers to malicious code if an action repository is compromised [4][2]. Pinning to a specific commit SHA ensures that your workflow consistently runs the exact, audited version of the code, mitigating the risk of unauthorized changes [1][5]. To implement this practice effectively while maintaining maintainability: 1. Use the full 40-character commit SHA: Reference actions using the format owner/repo@<full-sha> [1][5]. 2. Include a trailing version comment: To ensure that automated tools like Dependabot and Renovate can still track and suggest updates, include the human-readable version as a comment on the same line [4][5]. For example: uses: actions/checkout@1d96e77 # v4.2.0 [5] 3. Enforce via policy: Administrators can enforce SHA pinning at the organization or repository level through GitHub Actions policies [1][6]. When enabled, workflows will fail if they attempt to use actions that are not pinned to a full commit SHA [6]. 4. Automate maintenance: Configure Dependabot (using the github-actions package ecosystem) to automatically manage these dependencies; it is designed to recognize and update both the SHA and the associated version comment simultaneously [4][5]. This approach provides a secure, immutable foundation for your workflows while allowing for manageable, auditable updates over time [4][5].
Citations:
- 1: https://docs.github.com/en/actions/reference/security/secure-use
- 2: https://www.stepsecurity.io/blog/pinning-github-actions-for-enhanced-security-a-complete-guide
- 3: https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md
- 4: https://starsling.dev/best-practices/github-actions/pin-action-shas
- 5: https://tomodahinata.com/en/blog/dependabot-github-actions-sha-pinning-supply-chain-security-guide
- 6: https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions/
Pin the Podman action to an immutable SHA.
redhat-actions/podman-install@main is a mutable branch reference, so the action code can change without a workflow review. Use a full-length commit SHA (for example with a version comment) instead.
Suggested fix
- uses: redhat-actions/podman-install@main
+ uses: redhat-actions/podman-install@<verified-40-character-commit-sha>🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/qemu-kvm-integration-tests.yml around lines 129 - 131,
Update the “Ensure use of podman 5” step to replace the mutable
redhat-actions/podman-install@main reference with a full-length immutable commit
SHA, optionally retaining a comment identifying the pinned version.
It's time to test with F44 and drop F42.
Use ansible-core 2.21 for testing - this is now the latest stable version.
Deprecate podman 5 install hack in favor of official github action
Signed-off-by: Rich Megginson rmeggins@redhat.com
Summary by CodeRabbit
Tests
Chores