Skip to content

fix(utils): recognize GitHub-hosted ARM64 Ubuntu and Windows runner labels (#449) - #451

Merged
fproulx-boostsecurity merged 3 commits into
boostsecurityio:mainfrom
Tyagiquamar:fix-arm64-runner-labels
Oct 2, 2026
Merged

fproulx-boostsecurity merged 3 commits into
boostsecurityio:mainfrom
Tyagiquamar:fix-arm64-runner-labels

Conversation

@Tyagiquamar

Copy link
Copy Markdown
Contributor

Problem

pr_runs_on_self_hosted flags GitHub-hosted ARM64 runner labels (such as ubuntu-24.04-arm, ubuntu-22.04-arm, windows-11-arm, and windows-11-vs2026-arm) as self-hosted runners because the runner matching regex in opa/rego/poutine/utils.rego does not account for -arm suffixes on versioned Linux or Windows 11 runner labels.

Root Cause

job_uses_self_hosted_runner in opa/rego/poutine/utils.rego matched runner strings against ubuntu-(([0-9]{2})\.04|...) and windows-(20[0-9]{2}|...), omitting optional -arm suffixes for Ubuntu labels and Windows 11 ARM variants.

Fix

  • Updated job_uses_self_hosted_runner regex in opa/rego/poutine/utils.rego to support ubuntu-NN.NN-arm and windows-11(-vsNNNN)?-arm.
  • Added test cases for ubuntu-24.04-arm, ubuntu-22.04-arm, windows-11-arm, and windows-11-vs2026-arm in opa/opa_test.go.

Verification

go test ./opa passed cleanly (100% test suite green).

Fixes #449

@Tyagiquamar
Tyagiquamar requested a review from a team as a code owner September 14, 2026 09:44
@Tyagiquamar

Copy link
Copy Markdown
Contributor Author

Hi, just following up on this when you get a chance. The branch is up to date and checks are green. If it looks good from your side, it should be ready to merge. Happy to make any changes if needed. Thanks!

@fproulx-boostsecurity

Copy link
Copy Markdown
Contributor

Hi, just following up on this when you get a chance. The branch is up to date and checks are green. If it looks good from your side, it should be ready to merge. Happy to make any changes if needed. Thanks!

sorry, just noticed this. will have a look

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Add coverage for ubuntu-26.04-arm and scanner integration fixtures.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Updates runner detection so GitHub-hosted ARM64 Ubuntu and Windows labels are not misclassified as self-hosted.

Changes:

  • Extends the Rego runner regex for ARM64 labels.
  • Adds Ubuntu and Windows ARM64 regression tests.
File Description
opa/​rego/​poutine/​utils.rego Recognizes ARM64 hosted runner labels.
opa/​opa_test.go Adds regression tests for ARM64 labels.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread opa/opa_test.go
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: François Proulx <76956526+fproulx-boostsecurity@users.noreply.github.com>
Signed-off-by: François Proulx <76956526+fproulx-boostsecurity@users.noreply.github.com>
@fproulx-boostsecurity
fproulx-boostsecurity merged commit acedd43 into boostsecurityio:main Oct 2, 2026
4 checks passed
@fproulx-boostsecurity

Copy link
Copy Markdown
Contributor

Sorry for the delay @Tyagiquamar , merged now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pr_runs_on_self_hosted: ARM64 hosted runner labels misdetected as self-hosted

4 participants