• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

NVIDIA / nodewright / 36494213540
83%

Build:
DEFAULT BRANCH: main
Ran 28 Sep 2026 11:04PM UTC
Jobs 1
Files 59
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 10:45PM UTC coverage: 82.444% (-0.04%) from 82.479%
36494213540

push

github

web-flow
feat(ci): attest SBOM and VEX to each platform manifest (#643)

A CycloneDX SBOM describes exactly one root filesystem. Attached to a
multi-platform index it honestly describes neither child, and a consumer
who resolves linux/amd64 and enumerates referrers on that manifest finds
nothing. The operator and agent images were doing exactly that.

Adds a composite action that resolves each platform's child manifest with
`crane digest --platform`, generates a per-platform SBOM, projects
.openvex.json onto that platform's digest, and attests both to the manifest
they describe. The signature and SLSA provenance stay on the index, which is
what a user pulls and what admission control resolves a tag to.

Resolution fails closed three ways: a malformed digest, a platform digest
equal to the index digest (crane returns a plain manifest's own digest, so
equality means the image is single-arch), and two platforms resolving to the
same digest. Only the first is caught by crane itself.

Every cosign call now pins --new-bundle-format=true and is bounded by a
timeout, and the cosign version is pinned across all three actions that run
it. The chart's signing path is included: leaving it on the installer's
default while verification hard-pins a version is what would break a release
the next time the installer SHA moves.

Adds a `tools` module holding `openvex`, a two-subcommand binary that binds
the committed document to a platform digest and validates it against the
OpenVEX v0.2.0 contract. It has no third-party dependencies on purpose, so
the release job runs it with a toolchain and no module download. Source mode
accepts an empty statements array, which is a deliberate divergence from the
sibling implementation in NVIDIA/aicr: this document is legitimately empty,
because every finding measured on the released images is genuinely present
and genuinely fixable.

A nested `tools/tests` module pins the evidence policy. The layout is
rendered to a golden file so a moved su... (continued)

9364 of 11358 relevant lines covered (82.44%)

7.63 hits per line

Coverage Regressions

Lines Coverage ∆ File
6
79.85
-0.19% operator/internal/controller/skyhook_controller.go
Jobs
ID Job ID Ran Files Coverage
1 36494213540.1 28 Sep 2026 11:04PM UTC 59
82.44
GitHub Action Run
Source Files on build 36494213540
  • Tree
  • List 59
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36494213540
  • 4fe17d2b on github
  • Prev Build on main (#36491515906)
  • Next Build on main (#36497038583)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc