Repository navigation
chore(dagger): bump platform CLI to v1.125.0 - #3560
Conversation
The release bump for v1.118.1 ran before platform v1.125.0 was in production, so the module still runs platform CLI v1.124.3. That version does not include the GitLab commit verification fixes or the writable /tmp in the CLI image. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
PR validation — ✅ 3 passing
AI Session Checks — 🟢 92% ·
|
| Avg score | Sessions | Failing policies | Attribution | Files | Lines | Total Duration |
|---|---|---|---|---|---|---|
| 🟢 92% | 1 | 100% AI / 0% Human | 1 | +1 / -1 | 15h38m19s |
🟢 92% — 100% AI — ⚠️ 1 policies failing
-
Oct 7, 2026 14:09 UTC · 15h38m19s · $131.17 · 1.7k in / 1.1M out · claude-code 2.1.292 (claude-opus-5-5)
Change Summary
-
- Fixes runner discovery so Dagger is chosen deterministically when GitLab context is also present.
- Improves GitLab commit verification token handling, status mapping, and user-facing warnings.
- Restores
signature.algorithmfallback rendering and threads GitLab token and CA support through the Dagger path. - Adds writable
/tmpsupport for the CLI image and validates the chain with targeted tests plus local and real-GitLab e2e runs.
AI Session Overall Score
-
🟢 92% — Strongly verified fix with only partial upfront planning and no diff-grounded scope check.
AI Session Analysis Breakdown
-
🟢 98% · verification
-
🟢 Targeted failing tests were turned green, then extended to local and real GitLab e2e. · High Impact
🟢 96% · user-trust-signal
-
🟢 User kept handing off follow-on tasks and ended by approving the PR opening. · High Impact
🟢 95% · solution-quality
-
🟢 Mutation checks showed the new GitLab verifier tests fail under the old logic. · High Impact
🟢 92% · alignment
-
No notes.
🟡 68% · context-and-planning
-
🟠 The main chainloop fix began from symptoms without a shared plan for the multi-file implementation. · Medium Severity
💡 For multi-axis fixes, publish a short step list before editing the first code path.
abstained · scope-discipline
-
🟡 Scope discipline was not diff-grounded because the reviewed commit diff never materialized. · Low Severity
Missing criteria: scope-discipline
-
File Attribution
████████████████████100% AI / 0% HumanStatus Attribution File Lines modified ai extras/dagger/main.go+1 / -1
Policies (4, 1 failing)
Status Policy Material Messages ✅ Passed ai-config-ai-agents-allowedai-coding-session-38d0eb- ✅ Passed ai-config-no-dangerous-commandsai-coding-session-38d0eb- ⚠️ Failedai-config-no-secretsai-coding-session-38d0eb- Secret (generic-api-key) detected in session content [turn=3115, source=tool_result, line=7]: unknown option: -c user.name=PFM7635-E2E-Bot -c user.email=pfm7635-e2e-bot@example.test -c gpg.program=gpg -c user.signingkey=[REDACTED:generic-api-key]
- Secret (generic-password) detected in session content [turn=2914, source=assistant-tool_use:Bash, line=1]: for c in gitlab-lab-ee gitlab-lab-ce; do echo "== $c"; docker inspect $c --format 'started={{.State.StartedAt}} health={{if .State.Health}}{{.State.Health.Status}}{{end}} compose={{index .Config.Label...
- Secret (generic-password) detected in session content [turn=3077, source=tool_result, line=2]: 32: -e GITLAB_OMNIBUS_CONFIG="external_url 'https://localhost:\$PORT'; letsencrypt['enable']=false; nginx['ssl_certificate']='/etc/gitlab/ssl/localhost.crt'; nginx['ssl_certificate_key']='/etc/gitlab/...
- Secret (generic-password) detected in session content [turn=3096, source=assistant-tool_use:Write, line=1]: {"content":"#!/usr/bin/env bash\n# Creates the isolated PFM-7635 e2e objects on gitlab-lab-ee. Tokens go to files only.\nset -euo pipefail\nE=$HOME/.cache/pfm7635-e2e\nAPI=https://localhost:8943/api/v...
- Secret (generic-password) detected in session content [turn=3433, source=tool_result, line=19]: --data-urlencode "[REDACTED:generic-password]=$pw" --data "skip_confirmation=true" | jq -r .id)
- Secret (generic-password) detected in session content [turn=3462, source=tool_result, line=2]: for c in gitlab-lab-ee gitlab-lab-ce; do echo "== $c"; docker inspect $c --format 'started={{.State.StartedAt}} health={{if .State.Health}}{{.State.Health.Status}}{{end}} compose={{index .Config.Label...
- Secret (generic-password) detected in session content [turn=3560, source=assistant-tool_use:Bash, line=1]: docker exec gitlab-lab-ee sh -c 'tail -n 30 /var/log/gitlab/puma/current | cut -c1-220' | grep -viE 'token|[REDACTED:generic-password]' | tail -15; echo ---; docker inspect gitlab-lab-ee --format 'mem...
- Secret (generic-password) detected in session content [turn=3586, source=assistant-tool_use:Write, line=1]: {"content":"#!/usr/bin/env bash\n# Creates the isolated PFM-7635 e2e objects on gitlab-lab-ee. Tokens go to files only.\n# The project lives in the bot user's namespace, so a hard delete of the bot re...
✅ Passed ai-config-mcp-servers-allowedai-coding-session-38d0eb- -
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
Scans not applied (3)
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
Security context
This change touches code with 2 recorded security-fix advisories. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.
View in Chainloop ↗ · How this works ↗
Powered by Chainloop and Chainloop Trace
Changes the platform (enterprise) CLI image of the Dagger module from v1.124.3 to v1.125.0.
The release bump for v1.118.1 set the platform version before platform v1.125.0 was in production. Thus the next module release would still run platform CLI v1.124.3. That version does not include the GitLab commit verification fixes from #3550. Its CLI image also does not have a writable
/tmp. With this change, the next module release runs a platform CLI that includes both.AI disclosure
This change was developed with assistance from Claude Code.