Skip to content

Image build cache improvements - #3971

Open
EmilyRagan wants to merge 4 commits into
mainfrom
image-build-cache-improvements
Open

EmilyRagan wants to merge 4 commits into
mainfrom
image-build-cache-improvements

Conversation

@EmilyRagan

@EmilyRagan EmilyRagan commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What changed

Updates to the build (and cache) action for COSMOS images to check for available updates when determining whether to serve cached images or rebuild; targets specific npm packages to upgrade in default npm installation

Why it changed

Trivy scans failing and reporting CVEs that have been fixed and would be pulled in by apt-get -y upgrade if the image was rebuilt, but image was cached based on hash of repo files that did not change so CVEs were not fixed

Testing strategy

CI

  • Cache STALE notices in pull step logs (lines 288, 323, 373, 442, 485 in this run) and passing trivy scans (openc3-node scan failed on the previously referenced run because of CVEs in outdated packages that ship with npm, follow-up commit updated openc3-node/Dockerfile to upgrade those packages to remove those CVEs)
  • no Cache STALE notices in the following run
  • passing trivy scan!!

Review notes

  • similar changes in PR for Enterprise OpenC3/cosmos-enterprise#794
  • sonarqube failure is existing/known reported issue about using "latest" tag

@EmilyRagan EmilyRagan self-assigned this Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.13%. Comparing base (0d8985e) to head (61dc6ca).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3971      +/-   ##
==========================================
+ Coverage   80.06%   80.13%   +0.07%     
==========================================
  Files         901      901              
  Lines       68370    68370              
  Branches     2699     2699              
==========================================
+ Hits        54738    54789      +51     
+ Misses      12976    12919      -57     
- Partials      656      662       +6     
Flag Coverage Δ
frontend 67.05% <ø> (+0.47%) ⬆️
python 80.13% <ø> (+<0.01%) ⬆️
ruby-api 82.42% <ø> (-0.19%) ⬇️
ruby-backend 85.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@EmilyRagan
EmilyRagan force-pushed the image-build-cache-improvements branch from c876d61 to e11d687 Compare October 1, 2026 18:06
@EmilyRagan
EmilyRagan marked this pull request as ready for review October 1, 2026 18:37

if docker pull "$src" 2>/dev/null; then
docker tag "$src" "docker.io/openc3inc/${name}:${TAG}"
if [ "$PUSH_CACHE" = "true" ] && [[ " $PROBE_IMAGES " == *" $name "* ]]; then

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The probe only catches upstream fixes that show up as pending OS package
upgrades. Bases like ruby:3.4-slim-trixie, valkey/valkey:9.1.2-trixie
and traefik:v3.7.13 get republished under the same tag (patched
Ruby/Valkey/Traefik binaries, Go CVE rebuilds). With no package delta, the
probe returns 0 and the stale cached image is served.

Suggest mixing each external base's digest into the cache key in the hash
step, so a republished tag becomes a normal miss and cascades to children:

d=$(docker buildx imagetools inspect "$base_ref" \
  --format '{{json .Manifest.Digest}}' 2>/dev/null | tr -d '"')
own="${own}-${d#sha256:}"

base_ref could be a fourth column in the spec heredoc. On a failed
lookup, warn and skip pushing that entry rather than caching under a key
that claims fresh.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great call out, thanks!

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please address @mcosgriff comments then LGTM!

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jmthomas @mcosgriff I believe this is addressed by my most recent commit, please re-review!

The package probe cannot see upstream bases republished under the same
tag (ruby, valkey, traefik, node), so a stale cached image was served.
Mix each external base's registry digest into the cache key; a failed
lookup builds the image but skips pushing it.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@EmilyRagan
EmilyRagan requested a review from mcosgriff October 1, 2026 22:25

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants