Skip to content

build: Update workflow - #13

Merged
kroese merged 5 commits into
masterfrom
work
Sep 26, 2026
Merged

kroese merged 5 commits into
masterfrom
work

Conversation

@kroese

@kroese kroese commented Sep 26, 2026

Copy link
Copy Markdown

No description provided.

Copilot AI lite review requested due to automatic review settings September 26, 2026 13:07
@kroese
kroese merged commit 5d3d25a into master Sep 26, 2026
1 of 2 checks passed
@kroese
kroese deleted the work branch September 26, 2026 13:07
Comment thread Dockerfile
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always
EOF
RUN openssl req \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚫 [hadolint] <DL1000> reported by reviewdog 🐶
unexpected 'R'
expecting a new line followed by the next instruction

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical supply-chain and secret-handling issues remain unresolved.

Review effort: Lite
Findings: 3 High severity

Open (3)
What changed in this PR

Updates the Windows VirtIO GPU build and release pipeline with Docker/BuildKit automation and pull-request review integration.

Changes:

  • Adds multi-stage driver, toolchain, signing, and packaging builds.
  • Automates validation, caching, artifact handling, and releases.
  • Integrates a reusable pull-request review workflow.
File Summary Review notes
Dockerfile Defines the reproducible driver build and packaging pipeline. Critical concerns: mutable root-executed Rust installer and private key persisted in exported build layers.
.github/​workflows/​build.yml Orchestrates builds, validation, caching, releases, and notifications. Reviewed; no final comment supplied.
.github/​workflows/​review.yml Invokes the shared pull-request review workflow. Critical concern: mutable external workflow reference runs with write permissions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

jobs:
review:
name: review
uses: action-pack/.github/.github/workflows/review.yml@master
Comment thread Dockerfile
Comment on lines +80 to +82
RUN curl --proto '=https' --tlsv1.2 --fail --location \
https://sh.rustup.rs -o /tmp/rustup.sh \
&& sh /tmp/rustup.sh -y --no-modify-path --profile minimal --default-toolchain none \
Comment thread Dockerfile
Comment on lines +451 to +452
-keyout /opt/test-cert/key.pem \
-out /opt/test-cert/cert.pem \
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants