Skip to content

feat: allow inheritance of devcontainer.metadata in the re-usable workflows#1357

Merged
Ron (rjaegers) merged 15 commits into
mainfrom
refactor/reduce-metadata-duplication
Jul 20, 2026
Merged

feat: allow inheritance of devcontainer.metadata in the re-usable workflows#1357
Ron (rjaegers) merged 15 commits into
mainfrom
refactor/reduce-metadata-duplication

Conversation

@rjaegers

Copy link
Copy Markdown
Member

🚀 Hey, I have created a Pull Request

Description of changes

This pull request introduces significant improvements to how devcontainer metadata is managed and merged across image flavors, enhances the CI/CD workflows for building and testing images, and adds new integration tests for base image validation. The most important changes include implementing a script and workflow logic to merge devcontainer.metadata labels according to the Dev Container spec, updating metadata and extension lists for devcontainer flavors, and expanding test coverage for base image contents.

Devcontainer metadata management and merging:

  • Added .github/scripts/merge-devcontainer-metadata.sh to merge the base image's devcontainer.metadata array with the current flavor's metadata, ensuring proper inheritance and avoiding duplication as per the Dev Container specification.
  • Updated workflows (.github/workflows/wc-build-push.yml, .github/workflows/build-push-test.yml, .github/workflows/wc-build-push-test.yml) to use the new merge script, pass base image references, and verify the merged metadata label on built images. [1] [2] [3] [4] [5] [6]

Devcontainer flavor metadata and extension updates:

  • Added .devcontainer/base/devcontainer-metadata.json and updated all flavor-specific devcontainer-metadata.json files to streamline extension lists, remove redundant entries, and unify formatter settings. [1] [2] [3] [4] [5] [6]
  • Updated README.md to document the new metadata merging approach and its rationale.

Base image and flavor build/test improvements:

  • Added a dummy compile_commands.json to /root/.amp in the C++ Dockerfile to improve compatibility with tools like SonarLint and Clangd.
  • Included the base flavor in the update-dependencies workflow matrix for comprehensive dependency management.

Test coverage enhancements:

  • Added new integration tests in test/base/integration-tests.bats to verify that all apt packages are installed at their pinned versions, tools from the inventory are present, the C.UTF-8 locale is set, and bash-completion is enabled for root.

These changes collectively improve maintainability, correctness, and developer experience when working with devcontainer images and their metadata.

✔️ Checklist

  • I have followed the contribution guidelines for this repository
  • I have added tests for new behavior, and have not broken any existing tests
  • I have added or updated relevant documentation
  • I have verified that all added components are accounted for in the SBOM
  • I understand the image size delta and agree the functionality justifies it

Copilot AI review requested due to automatic review settings July 13, 2026 13:03
@rjaegers
Ron (rjaegers) requested a review from a team as a code owner July 13, 2026 13:03
@rjaegers Ron (rjaegers) changed the title Refactor/reduce metadata duplication refactor: reduce metadata duplication Jul 13, 2026
@rjaegers Ron (rjaegers) changed the title refactor: reduce metadata duplication feat: allow inheritance of devcontainer.metadata in the re-usable workflows Jul 13, 2026
@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-base:edgeghcr.io/philips-software/amp-devcontainer-base:pr-1357

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 75.35 MB 75.35 MB 52 B (0%) 🔽
linux/arm64 73.43 MB 73.43 MB 215 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 23 0 0 0.25s
✅ DOCKERFILE hadolint 4 0 0 0.27s
✅ JSON npm-package-json-lint yes no no 0.51s
✅ JSON prettier 43 2 0 0 0.89s
✅ JSON v8r 43 0 0 16.62s
✅ MARKDOWN markdownlint 13 0 0 0 1.28s
✅ MARKDOWN markdown-table-formatter 13 0 0 0 0.27s
✅ REPOSITORY betterleaks yes no no 1.14s
✅ REPOSITORY checkov yes no no 30.27s
✅ REPOSITORY gitleaks yes no no 1.18s
✅ REPOSITORY git_diff yes no no 0.02s
✅ REPOSITORY grype yes no no 69.26s
⚠️ REPOSITORY osv-scanner yes 1 no 0.73s
✅ REPOSITORY secretlint yes no no 2.09s
✅ REPOSITORY syft yes no no 2.74s
✅ REPOSITORY trivy yes no no 15.71s
✅ REPOSITORY trivy-sbom yes no no 0.25s
✅ REPOSITORY trufflehog yes no no 6.97s
⚠️ SPELL lychee 111 2 0 10.43s
✅ YAML prettier 32 0 0 0 1.29s
✅ YAML v8r 32 0 0 14.6s
✅ YAML yamllint 32 0 0 1.57s

Detailed Issues

⚠️ SPELL / lychee - 2 errors
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....147
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........2
⛔ Unsupported......2

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden

Errors in README.md
[ERROR] https://securityscorecards.dev/viewer/?uri=github.com/philips-software/amp-devcontainer (at 4:599) | Connection failed. Check network connectivity and firewall settings

Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 error
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned package-lock.json file and found 73 packages
End status: 107 dirs visited, 346 inodes visited, 8 Extract calls, 36.180313ms elapsed, 36.180514ms wall time

Total 2 packages affected by 2 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 2 Unknown) from 1 ecosystem.
0 vulnerabilities can be fixed.

+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| OSV URL                           | CVSS | ECOSYSTEM | PACKAGE    | VERSION | FIXED VERSION | SOURCE                                            |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110 |      | crates.io | bare-metal | 0.2.5   | --            | test/embedded-rust/workspace/cortex-m/Cargo.lock  |
| https://osv.dev/RUSTSEC-2026-0110 |      | crates.io | bare-metal | 0.2.5   | --            | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR reduces duplication in devcontainer metadata across image flavors by introducing a metadata-merge script and wiring it into the build/push workflows, while also updating per-flavor metadata payloads and expanding base image integration tests.

Changes:

  • Add a script to merge devcontainer.metadata arrays (base + flavor) and verify the resulting label on pushed images.
  • Refactor per-flavor devcontainer-metadata.json to remove base-duplicated entries and centralize base defaults.
  • Expand base integration tests to validate pinned apt package versions, tool inventory presence, locale defaults, and bash-completion.

Reviewed changes

Copilot reviewed 13 out of 13 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
test/base/integration-tests.bats Adds additional base-image verification tests (apt pins, tool inventory, locale, bash completion).
README.md Documents the metadata-array inheritance/merge approach for flavors and derived images.
.github/workflows/wc-build-push.yml Generates merged devcontainer.metadata label and verifies it on the pushed image.
.github/workflows/wc-build-push-test.yml Plumbs base-image reference input through to the lower-level build workflow.
.github/workflows/update-dependencies.yml Includes base flavor in the dependency update matrix.
.github/workflows/build-push-test.yml Passes base image reference so flavor builds can merge inherited metadata.
.github/scripts/merge-devcontainer-metadata.sh New helper to concatenate base + flavor devcontainer.metadata arrays per spec behavior.
.devcontainer/base/devcontainer-metadata.json New base metadata entry to be inherited by flavors via array merging.
.devcontainer/cpp/Dockerfile Creates a default compile_commands.json location for tooling compatibility.
.devcontainer/cpp/devcontainer-metadata.json Updates C++ flavor extensions/settings to rely on inherited base metadata.
.devcontainer/embedded-cpp/devcontainer-metadata.json Updates embedded C++ flavor extensions/settings to rely on inherited base metadata.
.devcontainer/docs/devcontainer-metadata.json Streamlines docs flavor extension list.
.devcontainer/rust/devcontainer-metadata.json Streamlines rust flavor extension list.

Comment thread .devcontainer/cpp/devcontainer-metadata.json
Comment thread .devcontainer/embedded-cpp/devcontainer-metadata.json
Comment thread test/base/integration-tests.bats Outdated
Comment thread .github/scripts/merge-devcontainer-metadata.sh Outdated
@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-docs:edgeghcr.io/philips-software/amp-devcontainer-docs:pr-1357

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 200.14 MB 200.14 MB 489 B (0%) 🔽
linux/arm64 196.35 MB 196.34 MB 788 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-rust:edgeghcr.io/philips-software/amp-devcontainer-rust:pr-1357

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 406.02 MB 406.02 MB 30 B (0%) 🔽
linux/arm64 357.58 MB 357.58 MB 434 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-cpp:edgeghcr.io/philips-software/amp-devcontainer-cpp:pr-1357

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 372.13 MB 372.13 MB 1.21 kB (0%) 🔽
linux/arm64 352.26 MB 352.26 MB 585 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-cpp:edgeghcr.io/philips-software/amp-devcontainer-embedded-cpp:pr-1357

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 560.5 MB 560.5 MB +1.45 kB (+0%) 🔼
linux/arm64 538.95 MB 538.95 MB 272 B (0%) 🔽

@github-actions

github-actions Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

Test Results

 25 files  ± 0   25 suites  ±0   20m 53s ⏱️ + 3m 27s
 48 tests + 4   48 ✅ + 4  0 💤 ±0  0 ❌ ±0 
201 runs  +16  201 ✅ +16  0 💤 ±0  0 ❌ ±0 

Results for commit baea69a. ± Comparison against base commit 7283164.

♻️ This comment has been updated with latest results.

Copilot AI review requested due to automatic review settings July 14, 2026 11:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated 4 comments.

Comment thread test/base/integration-tests.bats
Comment thread test/base/integration-tests.bats
Comment thread .devcontainer/cpp/devcontainer-metadata.json
Comment thread .devcontainer/embedded-cpp/devcontainer-metadata.json

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM but those AI comments are worth checking, especially the bats ones (I don't know enough of bats to say how valid they are).

Signed-off-by: Ron <45816308+rjaegers@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 15, 2026 19:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 13 out of 13 changed files in this pull request and generated 1 comment.

Comment thread test/base/integration-tests.bats
@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

📦 Container Size Analysis

Note

Comparing ghcr.io/philips-software/amp-devcontainer-embedded-rust:edgeghcr.io/philips-software/amp-devcontainer-embedded-rust:pr-1357

📈 Size Comparison Table

OS/Platform Previous Current Change Trend
linux/amd64 469.09 MB 469.09 MB 704 B (0%) 🔽
linux/arm64 419.88 MB 419.88 MB +164 B (+0%) 🔼

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Comment thread .github/scripts/merge-devcontainer-metadata.sh
Comment thread test/base/integration-tests.bats
Copilot AI review requested due to automatic review settings July 15, 2026 20:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 14 out of 14 changed files in this pull request and generated 3 comments.

Comment thread test/base/integration-tests.bats
Comment thread test/base/integration-tests.bats Outdated
Comment thread .github/scripts/merge-devcontainer-metadata.sh Outdated
@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 15, 2026 20:33 — with GitHub Actions Inactive
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Ron <45816308+rjaegers@users.noreply.github.com>
Copilot AI review requested due to automatic review settings July 16, 2026 14:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 14 out of 14 changed files in this pull request and generated 2 comments.

Comment thread test/base/integration-tests.bats
Comment thread .github/scripts/merge-devcontainer-metadata.sh

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 16 out of 16 changed files in this pull request and generated 2 comments.

Comment thread .github/scripts/merge-devcontainer-metadata.sh Outdated
Comment thread .github/workflows/wc-build-push.yml Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Ron <45816308+rjaegers@users.noreply.github.com>
@rjaegers
Ron (rjaegers) enabled auto-merge July 20, 2026 09:09
@sonarqubecloud

Copy link
Copy Markdown

@rjaegers
Ron (rjaegers) temporarily deployed to acceptance-testing July 20, 2026 09:36 — with GitHub Actions Inactive
@rjaegers
Ron (rjaegers) added this pull request to the merge queue Jul 20, 2026
Merged via the queue into main with commit 0869d12 Jul 20, 2026
91 checks passed
@rjaegers
Ron (rjaegers) deleted the refactor/reduce-metadata-duplication branch July 20, 2026 10:08
@github-actions

Copy link
Copy Markdown
Contributor

Pull Request Report (#1357)

Static measures

Description Value
Number of added lines 199
Number of deleted lines 63
Number of changed files 16
Number of commits 15
Number of reviews 9
Number of comments (w/o review comments) 9
Number of reviews that contains a comment to resolve 8
Number of reviews that requested a change from the author 0
Number of reviews that approved the Pull Request 1
Get the total number of participants of a Pull Request 6

Time related measures

Description Value
PR lead time (from creation to close of PR) 6.9 Days
Time that was spend on the branch before the PR was created 5.2 Hours
Time that was spend on the branch before the PR was merged 7.1 Days
Time to merge after last review 3.8 Days

Status check related measures

Description Value
Total runtime for last status check run (Workflow for PR) 1.7 Hours
Total time spend in last status check run on PR 22.1 Min

@github-actions

Copy link
Copy Markdown
Contributor

🎉 Hooray! The changes in this pull request went live with the release of v8.0.0 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants