Skip to content

[codex] Fix verifier auto-install and cosign bundles - #2481

Merged
Andriy Knysh (aknysh) merged 2 commits into
mainfrom
osterman/fix-windows-cosign-install
May 23, 2026
Merged

Andriy Knysh (aknysh) merged 2 commits into
mainfrom
osterman/fix-windows-cosign-install

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented May 22, 2026 •

Copy link
Copy Markdown
Member

what

  • Resolve verifier auto-installs to concrete registry versions before bootstrapping, instead of falling back to literal latest.
  • Add platform-aware installer helpers and regression coverage for Windows verifier asset URLs across cosign, slsa-verifier, gh, and minisign.
  • Combine cosign opts with downloaded sidecars like --bundle so Trivy checksum signature verification works with Aqua metadata.

why

  • Windows CI was failing because cosign release assets exist under v... tags and the bootstrap path could construct invalid release URLs.
  • Trivy verification failed on macOS because Atmos dropped the sigstore bundle whenever cosign options were present, producing an incomplete cosign verify-blob command.
  • The added tests cover the failing Windows URL rendering path and the Trivy-shaped checksum signature command.

references

  • Fixes the verifier install failure introduced by package verification.
  • Validated with go test ./pkg/toolchain/installer ./pkg/toolchain/registry/aqua ./pkg/toolchain/verification, go test ./pkg/toolchain, pre-commit hooks, and a live go run . toolchain install aquasecurity/trivy@v0.70.0.

Summary by CodeRabbit

  • New Features

    • Signature verification now supports bundle sidecars.
    • Enhanced cross-platform asset resolution, including better Windows ARM and Rosetta2 handling and per-platform overrides.
    • Improved verifier bootstrap resolution with additional fallback behavior.
  • Bug Fixes

    • Corrected Windows executable extension handling across target platforms.
  • Tests

    • Added tests for Windows asset URL generation, verifier version resolution failures, and cosign bundle sidecar integration.

Review Change Stack

@atmos-pro

atmos-pro Bot commented May 22, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions github-actions Bot added the size/m Medium size PR label May 22, 2026
@github-actions

github-actions Bot commented May 22, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

@codecov

codecov Bot commented May 22, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 83.90805% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 78.24%. Comparing base (eab5ad7) to head (00e7b50).

Files with missing lines Patch % Lines
pkg/toolchain/installer/asset.go 86.36% 4 Missing and 2 partials ⚠️
pkg/toolchain/installer/installer.go 82.85% 3 Missing and 3 partials ⚠️
pkg/toolchain/verification/signature.go 60.00% 1 Missing and 1 partial ⚠️
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2481      +/-   ##
==========================================
+ Coverage   78.20%   78.24%   +0.04%     
==========================================
  Files        1119     1119              
  Lines      106283   106335      +52     
==========================================
+ Hits        83115    83202      +87     
+ Misses      18529    18490      -39     
- Partials     4639     4643       +4     
Flag Coverage Δ
unittests 78.24% <83.90%> (+0.04%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
pkg/toolchain/installer/override.go 100.00% <100.00%> (ø)
pkg/toolchain/verification/signature.go 70.28% <60.00%> (+0.42%) ⬆️
pkg/toolchain/installer/asset.go 89.67% <86.36%> (-2.97%) ⬇️
pkg/toolchain/installer/installer.go 81.86% <82.85%> (+0.35%) ⬆️

... and 6 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@osterman
Erik Osterman (Cloud Posse) (osterman) marked this pull request as ready for review May 22, 2026 23:43
@osterman Erik Osterman (Cloud Posse) (osterman) added the patch A minor, backward compatible change label May 22, 2026
@coderabbitai

coderabbitai Bot commented May 22, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Asset URL construction is refactored to accept explicit goos/goarch parameters throughout the builder chain. Verifier bootstrap version resolution is extracted into a dedicated method with a new error type. Platform override application is generalized to support cross-platform testing. Cosign signature verification now properly combines user options with downloaded bundle sidecars. Windows .exe handling is centralized through an OS-aware helper. Tests cover Windows asset URL scenarios and verifier bootstrap edge cases.

Changes

Platform-aware asset URL construction and verifier bootstrap refactoring

Layer / File(s) Summary
Platform-aware asset URL construction infrastructure
pkg/toolchain/installer/asset.go
BuildAssetURL now dispatches through platform-specific builders that accept goos/goarch and pass them through HTTP and GitHub release URL builders. Template data construction is refactored into smaller helpers that compute version strings, platform-specific OS/arch values (including Rosetta2 and Windows ARM emulation), and per-platform format overrides based on the provided platform rather than runtime.GOOS.
Windows .exe extension handling
pkg/toolchain/installer/asset.go, pkg/toolchain/installer/installer.go
ensureWindowsExeExtensionForOS centralized helper conditionally appends .exe based on the passed goos parameter. Both HTTP asset URLs and GitHub release asset names now use this helper instead of implicitly checking runtime.GOOS. EnsureWindowsExeExtension delegates to the new platform-aware helper.
Template helpers and per-platform formats
pkg/toolchain/installer/asset.go
buildTemplateData now delegates to buildTemplateDataForPlatform and related helpers (versionStringsForTool, templatePlatformValues, platformArchForTool, templateFormatForPlatform) to compute version, OS/arch template values, replacements, and format overrides using the provided platform.
Platform override application generalization
pkg/toolchain/installer/override.go
ApplyPlatformOverrides refactored to delegate to new exported ApplyPlatformOverridesForPlatform(tool, goos, goarch). The original function passes runtime.GOOS/runtime.GOARCH to the helper while preserving existing matching and logging logic.
Verifier version resolution extraction
pkg/toolchain/installer/installer.go, pkg/toolchain/installer/errors.go
New resolveVerifierInstallVersion method queries configured registries (when enabled) and falls back to an Aqua registry created by registryFactory. Lookup errors are aggregated and ErrVerifierVersionUnavailable is returned when no latest version is discoverable; verifierCommandRunner.Run now uses this method and wraps failures.
Cosign bundle sidecar verification
pkg/toolchain/verification/signature.go, pkg/toolchain/verification/checksum_test.go
cosignArgs now always attempts cosign sidecar downloads after rendering cfg.Opts, appending any resulting flags/paths instead of early-returning. If sidecars add no verification args, it returns nil to skip running cosign. A new test verifies combination of user-provided Cosign.Opts with downloaded bundle sidecar arguments.
Test coverage for Windows assets and verifier scenarios
pkg/toolchain/installer/asset_test.go, pkg/toolchain/installer/verifier_command_test.go
Table-driven tests validate Windows asset URL generation across raw binaries, archives, emulation, and registry replacement scenarios for windows/amd64. Verifier tests simulate lookup failures and confirm installer behavior when latest versions are unavailable.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • cloudposse/atmos#2107: Refactors asset.go with platform-aware template data construction, OS/arch replacements, Rosetta2/Windows ARM emulation handling, and per-OS format overrides overlapping with the main PR's asset URL changes.
  • cloudposse/atmos#2415: Touches toolchain verification and installer verifier execution pipeline, including cosign sidecar argument handling similar to the main PR's signature verification changes.

Suggested reviewers

  • aknysh
  • atmos-pro
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 7.14% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The PR title accurately describes the main changes: verifier auto-install fixes and cosign bundle handling improvements mentioned in the objectives.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/fix-windows-cosign-install

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
pkg/toolchain/installer/override.go (1)

21-23: ⚡ Quick win

Add a doc comment for the new exported function.

ApplyPlatformOverridesForPlatform is exported and should have a Go-style doc comment to keep docs/lint clean.

Suggested patch.
+// ApplyPlatformOverridesForPlatform applies platform-specific overrides using the provided GOOS/GOARCH values.
 func ApplyPlatformOverridesForPlatform(tool *registry.Tool, goos, goarch string) {
 	defer perf.Track(nil, "installer.ApplyPlatformOverridesForPlatform")()

As per coding guidelines, "Document all exported functions, types, and methods following Go's documentation conventions."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/toolchain/installer/override.go` around lines 21 - 23, Add a Go-style doc
comment for the exported function ApplyPlatformOverridesForPlatform: start the
comment with the function name and write one concise sentence describing what
the function does, and include brief notes about the parameters (tool
*registry.Tool, goos, goarch) and any important behavior or side-effects; place
the comment immediately above the ApplyPlatformOverridesForPlatform declaration
in override.go to satisfy Go documentation/lint rules.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@pkg/toolchain/installer/installer.go`:
- Around line 401-415: resolveVerifierInstallVersion currently ignores errors
returned by configuredReg.GetLatestVersion and reg.GetLatestVersion and only
returns a generic ErrVerifierVersionUnavailable; capture those lookup errors,
aggregate them with errors.Join, and return a wrapped error that includes
ErrVerifierVersionUnavailable (e.g., fmt.Errorf("%w: %s/%s",
errors.Join(collectedErrs...), owner, repo) or wrap Join result) so callers see
root causes. Specifically, in resolveVerifierInstallVersion collect non-nil
errors from i.configuredReg.GetLatestVersion and from reg.GetLatestVersion
(referencing i.useConfiguredReg, i.configuredReg,
i.registryFactory.NewAquaRegistry, and GetLatestVersion), join them with
errors.Join, and return the joined error wrapped with
ErrVerifierVersionUnavailable when no version is found.

---

Nitpick comments:
In `@pkg/toolchain/installer/override.go`:
- Around line 21-23: Add a Go-style doc comment for the exported function
ApplyPlatformOverridesForPlatform: start the comment with the function name and
write one concise sentence describing what the function does, and include brief
notes about the parameters (tool *registry.Tool, goos, goarch) and any important
behavior or side-effects; place the comment immediately above the
ApplyPlatformOverridesForPlatform declaration in override.go to satisfy Go
documentation/lint rules.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: b40cf68a-33e9-4143-8467-bdcaeb932ba2

📥 Commits

Reviewing files that changed from the base of the PR and between eab5ad7 and d6fa805.

📒 Files selected for processing (8)
  • pkg/toolchain/installer/asset.go
  • pkg/toolchain/installer/asset_test.go
  • pkg/toolchain/installer/errors.go
  • pkg/toolchain/installer/installer.go
  • pkg/toolchain/installer/override.go
  • pkg/toolchain/installer/verifier_command_test.go
  • pkg/toolchain/verification/checksum_test.go
  • pkg/toolchain/verification/signature.go

Comment thread pkg/toolchain/installer/installer.go

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
pkg/toolchain/installer/verifier_command_test.go (1)

125-155: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Track install attempts explicitly in this regression test.

assert.Empty(t, reg.requestedVersion, ...) cannot tell “Install was never called” from “Install was called with an empty version”. A buggy bootstrap path that reaches GetToolWithVersion(..., "") would still pass here.

Suggested fix.
 type verifierBootstrapRegistry struct {
 	mu               sync.Mutex
 	latest           string
 	latestErr        error
 	tool             *registry.Tool
 	requestedVersion string
+	getToolCalls     int
 }
 
 func (r *verifierBootstrapRegistry) GetToolWithVersion(_, _, version string) (*registry.Tool, error) {
 	r.mu.Lock()
 	defer r.mu.Unlock()
+	r.getToolCalls++
 	r.requestedVersion = version
 	return r.tool, nil
 }
-	assert.Empty(t, reg.requestedVersion, "bootstrap install must not be called with literal latest")
+	assert.Zero(t, reg.getToolCalls, "bootstrap install must not be attempted")

Also applies to: 205-221

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/toolchain/installer/verifier_command_test.go` around lines 125 - 155, The
test currently uses assert.Empty(t, reg.requestedVersion) which can’t
distinguish “no install attempt” from “install attempted with empty string”;
update verifierBootstrapRegistry to track attempts explicitly (e.g., add a bool
field like installCalled or attemptCount) and set it inside its
Install/GetToolWithVersion path, then in
TestVerifierCommandRunnerAutoInstallFailsBeforeInstallingLatest (and the other
case at 205-221) assert that reg.installCalled is false (or attemptCount == 0)
instead of checking requestedVersion; reference verifierBootstrapRegistry,
requestedVersion, and
TestVerifierCommandRunnerAutoInstallFailsBeforeInstallingLatest when making the
changes.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@pkg/toolchain/installer/verifier_command_test.go`:
- Around line 125-155: The test currently uses assert.Empty(t,
reg.requestedVersion) which can’t distinguish “no install attempt” from “install
attempted with empty string”; update verifierBootstrapRegistry to track attempts
explicitly (e.g., add a bool field like installCalled or attemptCount) and set
it inside its Install/GetToolWithVersion path, then in
TestVerifierCommandRunnerAutoInstallFailsBeforeInstallingLatest (and the other
case at 205-221) assert that reg.installCalled is false (or attemptCount == 0)
instead of checking requestedVersion; reference verifierBootstrapRegistry,
requestedVersion, and
TestVerifierCommandRunnerAutoInstallFailsBeforeInstallingLatest when making the
changes.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 219c944b-06ec-4af4-9c4b-5a8bec2c47a3

📥 Commits

Reviewing files that changed from the base of the PR and between d6fa805 and 00e7b50.

📒 Files selected for processing (2)
  • pkg/toolchain/installer/installer.go
  • pkg/toolchain/installer/verifier_command_test.go

@aknysh
Andriy Knysh (aknysh) merged commit fdaca44 into main May 23, 2026
58 checks passed
@atmos-pro

atmos-pro Bot commented May 23, 2026

Copy link
Copy Markdown
Contributor

Note

Atmos Pro  

Waiting for your GitHub Actions workflow to upload affected stacks.
Learn More.

@aknysh
Andriy Knysh (aknysh) deleted the osterman/fix-windows-cosign-install branch May 23, 2026 02:18
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request May 23, 2026
Pre-commit was failing on the merge ref for PR #2482 because three commits
recently merged to main (#2348, #2478, #2481) contain files that were not
gofumpt-formatted and a couple of native-ci test fixtures with trailing
whitespace from captured terraform output.

These files are not touched by this PR, but they appear in the PR's
GitHub-generated merge ref diff and so pre-commit checks them. Apply the
auto-fixes that pre-commit produces:

- cmd/terraform/output.go: group two consecutive var decls.
- internal/exec/terraform_output_getter_test.go: line-break in
  assert.PanicsWithValue calls (2x).
- pkg/terraform/output/executor_test.go: line-break in NewExecutor call.
- pkg/terraform/output/get_test.go: line-break in assert.PanicsWithValue
  calls (3x).
- tests/fixtures/scenarios/native-ci/github-output.txt: trim trailing
  whitespace.
- tests/fixtures/scenarios/native-ci/github-step-summary.txt: trim
  trailing whitespace.

The fixture files are runtime outputs set via GITHUB_OUTPUT and
GITHUB_STEP_SUMMARY env vars during the native-ci test scenarios and are
only checked via file_contains substring assertions, so trimming trailing
whitespace is safe.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Andriy Knysh (aknysh) added a commit that referenced this pull request May 25, 2026
…nd skip controls (#2482)

* feat(hooks): kind system + scanner kinds + auto-install + --skip-hooks

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(hooks): test coverage + error-builder polish + helper extraction

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore: apply gofumpt and trim trailing whitespace after main merge

Pre-commit was failing on the merge ref for PR #2482 because three commits
recently merged to main (#2348, #2478, #2481) contain files that were not
gofumpt-formatted and a couple of native-ci test fixtures with trailing
whitespace from captured terraform output.

These files are not touched by this PR, but they appear in the PR's
GitHub-generated merge ref diff and so pre-commit checks them. Apply the
auto-fixes that pre-commit produces:

- cmd/terraform/output.go: group two consecutive var decls.
- internal/exec/terraform_output_getter_test.go: line-break in
  assert.PanicsWithValue calls (2x).
- pkg/terraform/output/executor_test.go: line-break in NewExecutor call.
- pkg/terraform/output/get_test.go: line-break in assert.PanicsWithValue
  calls (3x).
- tests/fixtures/scenarios/native-ci/github-output.txt: trim trailing
  whitespace.
- tests/fixtures/scenarios/native-ci/github-step-summary.txt: trim
  trailing whitespace.

The fixture files are runtime outputs set via GITHUB_OUTPUT and
GITHUB_STEP_SUMMARY env vars during the native-ci test scenarios and are
only checked via file_contains substring assertions, so trimming trailing
whitespace is safe.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(snapshots): regenerate help snapshots for --skip-hooks global flag

The new --skip-hooks global flag added in pkg/flags/global_builder.go
appears in every command's --help output. Regenerated the 39 affected
golden snapshots so TestCLICommands passes on Linux, macOS, and Windows.

Also includes:
- pkg/hooks/hooks_test.go: save and restore prior viper "skip-hooks"
  value in TestRunAll_SkipHooksBypassesPreflightBinaryCheck to avoid
  cross-test viper leakage.
- website/src/data/roadmap.js: minor copy edit to custom-hooks milestone.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(ci): update test workflow checkout actions

* test(hooks): assert normalized legacy hook kind

* test: increase hooks coverage

* ci: disable checkout credential persistence

* ci: pin workflow actions

* docs: clarify custom hook outputs

* docs: rewrite tool-deps PRD as requirements; split scanner kinds; document hook env var lifetime and --all

Rewrite docs/prd/tool-dependencies-integration.md to state requirements
and per-feature implementation status instead of narrating its own
history. The PRD now leads with a Requirements & Implementation Status
table that flags each requirement as Implemented or Not implemented with
a code reference. Implementation Plan phases carry Status annotations.
Success Criteria are plain numbered items, not a completion tracker.

Split the lumped trivy/checkov/kics section in website/docs/stacks/hooks.mdx
into three separate sections, one per kind, each with a definition list
documenting that scanner's command, args, output handling, on_failure
default, runtime requirements, and kind-specific quirks (Checkov's
SSL_CERT_FILE workaround, KICS's KICS_QUERIES_PATH and curated registry
override).

Expand the ATMOS_OUTPUT_DIR / ATMOS_OUTPUT_FILE env-var entries to spell
out the per-hook-invocation contract: fresh os.MkdirTemp("atmos-hook-*")
directory created before the subprocess runs, deleted automatically when
the hook returns, never shared between sibling hooks.

Add a new "Hooks with --all" subsection covering per-component firing in
dependency order, per-component tool install, shared --skip-hooks, and
on_failure:fail aborting the downstream traversal.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(hooks): link examples to website routes; document override semantics; drop stream paragraph from changelog

Switch the Examples list in website/docs/stacks/hooks.mdx from raw
GitHub URLs to the website's /examples/<name> routes (the file-browser
plugin already publishes them).

Add an "Overriding Kind Defaults" section to hooks.mdx documenting that
any field set on a hook (command, args, env, on_failure) overrides the
named kind's default for that field. Includes a caution callout that
args and env are full replacement — not merge — so overriding args
requires restating the full default arg list. Three examples cover the
common cases: bumping a scanner's severity threshold via args, making a
finding block the run via on_failure, and injecting a tool config path
via env. Code path: pkg/hooks/kind.go::ResolveDefaults.

Drop the "Tool output streams naturally" subsection from the custom
hooks changelog entry per review feedback.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(hooks): signal overridable defaults up front in Built-in Kinds preamble

The per-kind sections list "(default)" values without indicating they're
customizable. Add a one-paragraph preamble under "Built-in Kinds" that
tells readers every default is overridable and points to the override
rules section before they read any individual kind.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(blog): link custom-hooks examples to /examples routes; add docs ActionCard

Swap the four GitHub example URLs in the custom-hooks changelog post to
the website's /examples/<name> routes (already published by the
file-browser plugin), matching the change in website/docs/stacks/hooks.mdx.

Append an ActionCard at the bottom pointing readers from the changelog
narrative to /stacks/hooks for the full reference (kinds, override
semantics, lifecycle events, tool auto-install, --all / --skip-hooks).

The remaining github.com URL in the "Try it" section stays — git clone
needs the GitHub URL.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(blog): add override-defaults chapter; wire ActionCard CTAs correctly

Add an "Override any default" h3 between the built-in-kinds and
bring-your-own-command sections, matching the chapter style of
"Workdir compatible". The new chapter shows that command, args, env,
and on_failure are all overridable on built-in kinds, with a worked
example (Trivy with HIGH,CRITICAL severity and on_failure: fail) and a
call-out that args/env are full replacement, not merge — linking to the
override docs at /stacks/hooks#overriding-kind-defaults.

Fix the closing ActionCard so the CTA buttons actually render. The
component reads ctaText/ctaLink and secondaryCtaText/secondaryCtaLink,
not href. The card now renders a primary "Read the docs" CTA to
/stacks/hooks and a secondary "Browse examples" CTA to
/examples/hooks-trivy.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Andriy Knysh <aknysh@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

These changes were released in v1.220.0-rc.2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch A minor, backward compatible change size/m Medium size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants