Skip to content

ci(cd)!: parallelize Burrito target builds and fix Trivy/Podman image scanning - #68

Merged
bougyman merged 1 commit into
mainfrom
issue-66
Aug 11, 2026
Merged

ci(cd)!: parallelize Burrito target builds and fix Trivy/Podman image scanning#68
bougyman merged 1 commit into
mainfrom
issue-66

Conversation

@bougyman

Copy link
Copy Markdown
Member

Summary

  • Splits the burrito job into a burrito-build matrix (one leg per target - macos_aarch64, linux_x86_64, windows_x86_64 - built concurrently instead of serially in one job) and a burrito-package job that gathers all three binaries and does the packaging/checksums/SBOM/release-creation. Closes ci: parallelize Burrito target builds across a matrix to cut release time from 12+ min to <5 #66. The release pipeline was taking 12+ minutes with all three targets built serially.
  • Fixes Trivy scanning a Docker-only image-ref while the image is actually built with Podman (ci/build_image.sh prefers Podman) - see Prefer Docker over Podman in container-image CI scripts #67, where a runtime-preference reorder was tried and rejected since it would've meant Podman-built images go untested. This saves the image to a tarball (ci/save_image.sh, already existed but was unused) and has Trivy scan that directly via its input option, sidestepping the runtime-detection question entirely.
  • Fixes a pre-existing shellcheck SC2035 nit (sha256sum * -> sha256sum -- *) found while validating the workflow with actionlint.

Test plan

  • actionlint .github/workflows/main.yaml - clean, no warnings
  • YAML validated (job graph: validate -> burrito-build (matrix) -> burrito-package -> container, with needs/output references updated accordingly)
  • End-to-end verification on an actual release-PR merge (or workflow_dispatch) - confirm total wall-clock and that the container SBOM step succeeds against the saved tarball

🤖 Generated with Claude Code

…scanning

Split the burrito job into a burrito-build matrix (one leg per target,
built concurrently) and a burrito-package job that assembles the
results - the release pipeline was taking 12+ minutes with all three
targets built serially in one job. Also fixes Trivy scanning a
Docker-only image-ref while the image is built with Podman (see #67)
by scanning a saved tarball instead of a live image-ref, sidestepping
the runtime-detection question entirely. Fixes a pre-existing
shellcheck SC2035 nit (sha256sum * -> sha256sum -- *) along the way.
Copilot AI lite review requested due to automatic review settings August 11, 2026 19:37
@bougyman bougyman changed the title ci(cd): parallelize Burrito target builds and fix Trivy/Podman image scanning ci(cd)!: parallelize Burrito target builds and fix Trivy/Podman image scanning Aug 11, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the release workflow to reduce end-to-end release time by parallelizing Burrito cross-target builds and to make container image scanning work reliably when the image is built with Podman.

Changes:

  • Split the former burrito workflow job into a burrito-build matrix (per-target parallel builds) plus a burrito-package job (packaging, checksums, SBOM, GitHub release creation).
  • Fix Trivy image scanning by saving the locally-built image to a tarball and scanning via Trivy’s input mode instead of image-ref.
  • Fix a shellcheck/actionlint nit by changing sha256sum * to sha256sum -- *.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/main.yaml
@bougyman
bougyman merged commit 5cc829a into main Aug 11, 2026
3 checks passed
@bougyman
bougyman deleted the issue-66 branch August 11, 2026 19:57
bougyman pushed a commit that referenced this pull request Aug 11, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.9.0](v0.8.5...v0.9.0)
(2026-08-11)


### ⚠ BREAKING CHANGES

* **cd:** parallelize Burrito target builds and fix Trivy/Podman image
scanning ([#68](#68))

### Continuous Integration

* **cd:** parallelize Burrito target builds and fix Trivy/Podman image
scanning ([#68](#68))
([5cc829a](5cc829a))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
This was referenced Aug 11, 2026
bougyman pushed a commit that referenced this pull request Aug 11, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.0.0](v1.0.0...v1.0.0)
(2026-08-11)


### ⚠ BREAKING CHANGES

* graduate to 1.0.0 - disable pre-major version bumping
([#70](#70))
* **cd:** parallelize Burrito target builds and fix Trivy/Podman image
scanning ([#68](#68))
* **ci:** rename release.yaml to main.yaml, workflow name to "main"
([#38](#38))
* add Readme/LICENSE, feat: wire up the issue list --project picker
([#12](#12))

### Features

* add mix githooks.install to activate the repo's git hooks
([#51](#51))
([9b35472](9b35472))
* **api:** add LinearCli.Api GraphQL client (Phase 1)
([723f3f6](723f3f6))
* **ci:** add a full SBOM - app deps, OTP/Elixir runtime, container OS
packages ([#54](#54))
([e296fdd](e296fdd))
* **cli:** add favorite teams/projects, filtering list views by them
([#61](#61))
([6c858d9](6c858d9))
* **cli:** add issue create/develop/pr/take/update write commands (Phase
6)
([1649618](1649618))
* **cli:** add profiles - default team/project stored in local SQLite
([#57](#57))
([554e336](554e336))
* **cli:** add project update - post a status update to a project
([#43](#43))
([30dc6dc](30dc6dc))
* **cli:** make version respect --output json
([#33](#33))
([b160aad](b160aad))
* **cli:** resolve bare issue numbers via active profile, favorited
teams, or a team prompt
([#65](#65))
([8b183da](8b183da))
* **cli:** support Ruby's short subcommand aliases
([#15](#15))
([9fca6b5](9fca6b5))
* initial commit with ash submodule
([c2ceafb](c2ceafb))
* **linear:** add Ash domain resources for
Issue/Project/Team/User/Label/WorkflowState/Comment (Phase 2)
([e2a27f3](e2a27f3))
* **oban:** add scheduled monthly project rollover (Phase 7)
([11afb43](11afb43))
* phase 4 from initial plan -&gt; complete
([012866e](012866e))
* phase 8 - packaging, releasing, and CI
([#1](#1))
([905c238](905c238))
* scaffold Elixir port and enforce conventional commits
([a4d03a0](a4d03a0))


### Bug Fixes

* **ci:** consolidate the release pipeline into one workflow/DAG
([ba821bb](ba821bb))
* **ci:** create releases as drafts so assets survive Immutable Releases
([#19](#19))
([8572623](8572623))
* **ci:** package release binaries with the wrapper scripts
([#24](#24))
([5fb24a4](5fb24a4))
* **ci:** rebuild the release pipeline to stop the version-bump runaway
loop ([#30](#30))
([c311fd4](c311fd4))
* **ci:** relabel the release PR as tagged after we tag it ourselves
([ab1408e](ab1408e))
* **ci:** skip commit-subject validation in the post-merge pipeline
([#41](#41))
([3d00a85](3d00a85))
* **cli:** reject unrecognized flags instead of treating them as issue
ids ([#2](#2))
([#4](#4))
([e697ff6](e697ff6))
* **deps:** update ash to a non-vulnerable version
([#63](#63))
([b838e2a](b838e2a))


### Performance Improvements

* **linear:** fan out find-by-ids and per-team project fetches (Phase 5)
([fb00153](fb00153))


### Documentation

* add Readme/LICENSE, feat: wire up the issue list --project picker
([#12](#12))
([eb42c69](eb42c69))


### Miscellaneous Chores

* **ci:** rename release.yaml to main.yaml, workflow name to "main"
([#38](#38))
([2581a40](2581a40))
* graduate to 1.0.0 - disable pre-major version bumping
([#70](#70))
([87a65ae](87a65ae))


### Continuous Integration

* **cd:** parallelize Burrito target builds and fix Trivy/Podman image
scanning ([#68](#68))
([5cc829a](5cc829a))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: parallelize Burrito target builds across a matrix to cut release time from 12+ min to <5

2 participants