Conversation
…scanning Split the burrito job into a burrito-build matrix (one leg per target, built concurrently) and a burrito-package job that assembles the results - the release pipeline was taking 12+ minutes with all three targets built serially in one job. Also fixes Trivy scanning a Docker-only image-ref while the image is built with Podman (see #67) by scanning a saved tarball instead of a live image-ref, sidestepping the runtime-detection question entirely. Fixes a pre-existing shellcheck SC2035 nit (sha256sum * -> sha256sum -- *) along the way.
There was a problem hiding this comment.
Pull request overview
This PR updates the release workflow to reduce end-to-end release time by parallelizing Burrito cross-target builds and to make container image scanning work reliably when the image is built with Podman.
Changes:
- Split the former
burritoworkflow job into aburrito-buildmatrix (per-target parallel builds) plus aburrito-packagejob (packaging, checksums, SBOM, GitHub release creation). - Fix Trivy image scanning by saving the locally-built image to a tarball and scanning via Trivy’s
inputmode instead ofimage-ref. - Fix a shellcheck/actionlint nit by changing
sha256sum *tosha256sum -- *.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
bougyman
pushed a commit
that referenced
this pull request
Aug 11, 2026
🤖 I have created a release *beep* *boop* --- ## [0.9.0](v0.8.5...v0.9.0) (2026-08-11) ### ⚠ BREAKING CHANGES * **cd:** parallelize Burrito target builds and fix Trivy/Podman image scanning ([#68](#68)) ### Continuous Integration * **cd:** parallelize Burrito target builds and fix Trivy/Podman image scanning ([#68](#68)) ([5cc829a](5cc829a)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This was referenced Aug 11, 2026
bougyman
pushed a commit
that referenced
this pull request
Aug 11, 2026
🤖 I have created a release *beep* *boop* --- ## [1.0.0](v1.0.0...v1.0.0) (2026-08-11) ### ⚠ BREAKING CHANGES * graduate to 1.0.0 - disable pre-major version bumping ([#70](#70)) * **cd:** parallelize Burrito target builds and fix Trivy/Podman image scanning ([#68](#68)) * **ci:** rename release.yaml to main.yaml, workflow name to "main" ([#38](#38)) * add Readme/LICENSE, feat: wire up the issue list --project picker ([#12](#12)) ### Features * add mix githooks.install to activate the repo's git hooks ([#51](#51)) ([9b35472](9b35472)) * **api:** add LinearCli.Api GraphQL client (Phase 1) ([723f3f6](723f3f6)) * **ci:** add a full SBOM - app deps, OTP/Elixir runtime, container OS packages ([#54](#54)) ([e296fdd](e296fdd)) * **cli:** add favorite teams/projects, filtering list views by them ([#61](#61)) ([6c858d9](6c858d9)) * **cli:** add issue create/develop/pr/take/update write commands (Phase 6) ([1649618](1649618)) * **cli:** add profiles - default team/project stored in local SQLite ([#57](#57)) ([554e336](554e336)) * **cli:** add project update - post a status update to a project ([#43](#43)) ([30dc6dc](30dc6dc)) * **cli:** make version respect --output json ([#33](#33)) ([b160aad](b160aad)) * **cli:** resolve bare issue numbers via active profile, favorited teams, or a team prompt ([#65](#65)) ([8b183da](8b183da)) * **cli:** support Ruby's short subcommand aliases ([#15](#15)) ([9fca6b5](9fca6b5)) * initial commit with ash submodule ([c2ceafb](c2ceafb)) * **linear:** add Ash domain resources for Issue/Project/Team/User/Label/WorkflowState/Comment (Phase 2) ([e2a27f3](e2a27f3)) * **oban:** add scheduled monthly project rollover (Phase 7) ([11afb43](11afb43)) * phase 4 from initial plan -> complete ([012866e](012866e)) * phase 8 - packaging, releasing, and CI ([#1](#1)) ([905c238](905c238)) * scaffold Elixir port and enforce conventional commits ([a4d03a0](a4d03a0)) ### Bug Fixes * **ci:** consolidate the release pipeline into one workflow/DAG ([ba821bb](ba821bb)) * **ci:** create releases as drafts so assets survive Immutable Releases ([#19](#19)) ([8572623](8572623)) * **ci:** package release binaries with the wrapper scripts ([#24](#24)) ([5fb24a4](5fb24a4)) * **ci:** rebuild the release pipeline to stop the version-bump runaway loop ([#30](#30)) ([c311fd4](c311fd4)) * **ci:** relabel the release PR as tagged after we tag it ourselves ([ab1408e](ab1408e)) * **ci:** skip commit-subject validation in the post-merge pipeline ([#41](#41)) ([3d00a85](3d00a85)) * **cli:** reject unrecognized flags instead of treating them as issue ids ([#2](#2)) ([#4](#4)) ([e697ff6](e697ff6)) * **deps:** update ash to a non-vulnerable version ([#63](#63)) ([b838e2a](b838e2a)) ### Performance Improvements * **linear:** fan out find-by-ids and per-team project fetches (Phase 5) ([fb00153](fb00153)) ### Documentation * add Readme/LICENSE, feat: wire up the issue list --project picker ([#12](#12)) ([eb42c69](eb42c69)) ### Miscellaneous Chores * **ci:** rename release.yaml to main.yaml, workflow name to "main" ([#38](#38)) ([2581a40](2581a40)) * graduate to 1.0.0 - disable pre-major version bumping ([#70](#70)) ([87a65ae](87a65ae)) ### Continuous Integration * **cd:** parallelize Burrito target builds and fix Trivy/Podman image scanning ([#68](#68)) ([5cc829a](5cc829a)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
burritojob into aburrito-buildmatrix (one leg per target -macos_aarch64,linux_x86_64,windows_x86_64- built concurrently instead of serially in one job) and aburrito-packagejob that gathers all three binaries and does the packaging/checksums/SBOM/release-creation. Closes ci: parallelize Burrito target builds across a matrix to cut release time from 12+ min to <5 #66. The release pipeline was taking 12+ minutes with all three targets built serially.image-refwhile the image is actually built with Podman (ci/build_image.shprefers Podman) - see Prefer Docker over Podman in container-image CI scripts #67, where a runtime-preference reorder was tried and rejected since it would've meant Podman-built images go untested. This saves the image to a tarball (ci/save_image.sh, already existed but was unused) and has Trivy scan that directly via itsinputoption, sidestepping the runtime-detection question entirely.shellcheckSC2035 nit (sha256sum *->sha256sum -- *) found while validating the workflow withactionlint.Test plan
actionlint .github/workflows/main.yaml- clean, no warningsvalidate->burrito-build(matrix) ->burrito-package->container, withneeds/output references updated accordingly)workflow_dispatch) - confirm total wall-clock and that the container SBOM step succeeds against the saved tarball🤖 Generated with Claude Code