Design and implement wizcli scan-context-id strategy
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 45/100
Research direction
Start with PR #715 and the existing WizCLICommand implementation to understand how bakery wizcli scan is wired into CI. Verify Wiz scan-context-id baselining and compare the release, dev, and matrix cases described here. Done means a documented stable ID strategy, optional CLI override support, reinstated scan-context-id wiring, and tests covering the agreed cases.
Written by the indexing model from the issue text.
Description
PR #715 adds bakery wizcli scan but does not set --scan-context-id,
so Wiz falls back to its own default grouping for baseline comparison.
We need to design and implement a context-id scheme that groups scans
into stable per-artifact baselines (image, version/channel, OS, variant,
platform) without conflating unrelated builds or generating a new
baseline on every patch bump or rebuild.
An earlier draft in #715 (commits 54552bf5, f8978daa, a3283202)
computed an ID like connect-2026-07-ubuntu-22-04-std-amd64 from image
name, release month (or dev channel), OS, variant, and platform, with
build metadata and Positron build-number suffixes stripped so patch
bumps update the same context in place. That logic was pulled out
before merge to keep #715 scoped to wiring the scan into CI; this
issue tracks getting the design and implementation right separately.
Scope:
- Decide the ID format for release, dev, and matrix versions
- Confirm how Wiz uses scan-context-id for baselining (repo + branch +
ID) and what granularity avoids false positives/negatives - Reinstate
--scan-context-idinWizCLICommand, with an optional
CLI passthrough for explicit overrides - Tests
Related:
- Dominant language
- Python
- Stars
- 2
- Forks
- 0
- Avg merge
- 2d 23h
- Merged PRs (30d)
- 20
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from posit-dev/images-shared
-
cvp:0 docker tdp:1
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
posit-dev/images-shared#757 · 2 comments ·
Maintainers usually reply within 1 day
-
bug cvp:0 docker priority/medium python tdp:1
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
posit-dev/images-shared#685 ·
Maintainers usually reply within 1 day
-
slack-build-notify: no persisted alert state — causes suppressed repeat-failure and recovery alertsOpenbug cicd cvp:0 docker needs discussion observability tdp:2
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
posit-dev/images-shared#677 ·
Maintainers usually reply within 1 day
-
cvp:0 docker tdp:2 tech debt
Difficulty 4/5 3-5 days Newbie friendliness 48/100
posit-dev/images-shared#795 ·
Maintainers usually reply within 1 day
-
cicd cvp:0 docker enhancement tdp:2
Difficulty 5/5 Over a week Newbie friendliness 35/100
posit-dev/images-shared#773 ·
Maintainers usually reply within 1 day
All issues in posit-dev/images-shared
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
qgis/QGIS-Plugins-Website#459 ·
-
bug severity:medium
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 2 days
-
bot-found bug priority: P3
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
madenvel/KalinkaPlayer#179 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
ls1intum/edutelligence#1098 ·
Maintainers usually reply within 1 day