Skip to content

Turn on CI/CD build for http-java17 example - #175

Open
chrisf-aarnet wants to merge 7 commits into
unikraft-cloud:mainfrom
chrisf-aarnet:main
Open

Turn on CI/CD build for http-java17 example#175
chrisf-aarnet wants to merge 7 commits into
unikraft-cloud:mainfrom
chrisf-aarnet:main

Conversation

@chrisf-aarnet

Copy link
Copy Markdown

There is currently no automated integration test for the http-java17 example or badge in the README.md.

This pull request adds the GitHub workflow to test this example (which seems currently to be failing).

Chris Fegan and others added 7 commits July 6, 2025 18:27
Remove the explicitly set runtime as CI/CD experiment

Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
Change to use the official java runtime.


specific argument:
--runtime index.unikraft.io/official/java:17 \


Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
Add more CI/CD debugging for java-http workflow


Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
Update the runtime for http-java CI/CD to one that exists

Signed-off-by: chrisf-aarnet <65877535+chrisf-aarnet@users.noreply.github.com>
nurof3n pushed a commit that referenced this pull request Mar 24, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
dragosgheorghioiu pushed a commit that referenced this pull request Apr 7, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
dragosgheorghioiu pushed a commit that referenced this pull request Apr 7, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
dragosgheorghioiu pushed a commit that referenced this pull request Apr 7, 2026
Update the following packages to fix security vulnerabilities:
- Authlib 1.6.5 -> 1.6.9 (critical: JWS JWK Header Injection, high: alg:none bypass, Bleichenbacher, OIDC hash binding, medium: account takeover)
- cryptography 46.0.3 -> 46.0.5 (high: SECT curve subgroup attack)
- fastmcp 2.13.2 -> 2.14.5 (high: OAuth proxy token reuse, MCP CVE-2025-66416)
- mcp 1.23.1 -> 1.26.0 (required by fastmcp 2.14.x)
- PyJWT 2.10.1 -> 2.12.1 (high: unknown crit header extensions)
- python-multipart 0.0.20 -> 0.0.22 (high: arbitrary file write)
- urllib3 2.5.0 -> 2.6.3 (high: decompression bomb bypass, streaming API issues)

Note: diskcache 5.6.3 has no fix available (alert #227).

Resolves dependabot alerts #175, #176, #184, #190, #198, #209, #225, #275, #283, #291, #293, #295, #297.

Signed-off-by: Razvan Deaconescu <razvand@unikraft.io>
@razvand
razvand requested a lite review from Copilot August 21, 2026 07:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds CI/CD coverage for the http-java17 example by introducing dedicated GitHub Actions workflows (stable + staging) and surfacing their status badges in the repository README, aligning this example with the other HTTP examples’ automation.

Changes:

  • Add http-java17 stable workflow to deploy and curl-test the example on Unikraft Cloud.
  • Add http-java17 staging workflow with the same integration flow plus cleanup and optional debug re-test.
  • Update README.md to include http-java17 workflow badges for stable and staging.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
README.md Adds the http-java17 example row with stable/staging workflow badges.
.github/workflows/example-http-java17-staging.yaml New staging integration workflow that deploys, tests via curl, and cleans up resources.
.github/workflows/example-http-java17-stable.yaml New stable integration workflow that deploys, tests via curl, and cleans up resources.
Suppressed comments (2)

.github/workflows/example-http-java17-stable.yaml:96

  • For consistency with other stable workflows (which use official-testing for both normal and -dbg images), the debug runtime here should also use the official-testing namespace.
            --runtime index.unikraft.io/official/java:17-dbg \

.github/workflows/example-http-java17-staging.yaml:96

  • The staging debug runtime should match the staging namespace used elsewhere (official-staging) so the -dbg re-test is validating the same environment as the main staging test.
            --runtime index.unikraft.io/official/java:17-dbg \

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

--no-start \
--memory 512 \
--name http-java17-${GITHUB_RUN_ID} \
--runtime index.unikraft.io/official/java:17 \
--no-start \
--memory 512 \
--name http-java17-${GITHUB_RUN_ID} \
--runtime index.unikraft.io/official/java:17 \
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants