Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

[None][infra] Fix source code scanning#12773

Merged
yuanjingx87 merged 1 commit intoNVIDIA:mainNVIDIA/TensorRT-LLM:mainfrom
yuanjingx87:user/yuanjingx/fix_source_code_scanningyuanjingx87/TensorRT-LLM:user/yuanjingx/fix_source_code_scanningCopy head branch name to clipboard
Apr 6, 2026
Merged

[None][infra] Fix source code scanning#12773
yuanjingx87 merged 1 commit intoNVIDIA:mainNVIDIA/TensorRT-LLM:mainfrom
yuanjingx87:user/yuanjingx/fix_source_code_scanningyuanjingx87/TensorRT-LLM:user/yuanjingx/fix_source_code_scanningCopy head branch name to clipboard

Conversation

@yuanjingx87
Copy link
Copy Markdown
Collaborator

@yuanjingx87 yuanjingx87 commented Apr 6, 2026

Summary by CodeRabbit

  • Chores
    • Updated build pipeline security scanning configuration to exclude specific detector types while generating software bill of materials.

Description

Disable pip inspector in PLC nightly pipeline

Test Coverage

PR Checklist

Please review the following before submitting your PR:

  • PR description clearly explains what and why. If using CodeRabbit's summary, please make sure it makes sense.

  • PR Follows TRT-LLM CODING GUIDELINES to the best of your knowledge.

  • Test cases are provided for new code paths (see test instructions)

  • Any new dependencies have been scanned for license and vulnerabilities

  • CODEOWNERS updated if ownership changes

  • Documentation updated as needed

  • Update tava architecture diagram if there is a significant design change in PR.

  • The reviewers assigned automatically/manually are appropriate for the PR.

  • Please check this after reviewing the above items as appropriate for this PR.

GitHub Bot Help

To see a list of available CI bot commands, please comment /bot help.

Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
@yuanjingx87 yuanjingx87 requested a review from a team as a code owner April 6, 2026 16:37
@yuanjingx87 yuanjingx87 requested a review from zeroepoch April 6, 2026 16:37
@yuanjingx87 yuanjingx87 requested a review from a team as a code owner April 6, 2026 16:37
@yuanjingx87 yuanjingx87 requested a review from mlefeb01 April 6, 2026 16:37
@yuanjingx87
Copy link
Copy Markdown
Collaborator Author

/bot skip --comment "no need to run CI"

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 6, 2026

GitHub Bot Help

/bot [-h] ['run', 'kill', 'skip', 'reuse-pipeline'] ...

Provide a user friendly way for developers to interact with a Jenkins server.

Run /bot [-h|--help] to print this help message.

See details below for each supported subcommand.

Details

run [--reuse-test (optional)pipeline-id --disable-fail-fast --skip-test --stage-list "A10-PyTorch-1, xxx" --gpu-type "A30, H100_PCIe" --test-backend "pytorch, cpp" --add-multi-gpu-test --only-multi-gpu-test --disable-multi-gpu-test --post-merge --extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx" --detailed-log --debug(experimental) --high-priority]

Launch build/test pipelines. All previously running jobs will be killed.

--reuse-test (optional)pipeline-id (OPTIONAL) : Allow the new pipeline to reuse build artifacts and skip successful test stages from a specified pipeline or the last pipeline if no pipeline-id is indicated. If the Git commit ID has changed, this option will be always ignored. The DEFAULT behavior of the bot is to reuse build artifacts and successful test results from the last pipeline.

--disable-reuse-test (OPTIONAL) : Explicitly prevent the pipeline from reusing build artifacts and skipping successful test stages from a previous pipeline. Ensure that all builds and tests are run regardless of previous successes.

--disable-fail-fast (OPTIONAL) : Disable fail fast on build/tests/infra failures.

--skip-test (OPTIONAL) : Skip all test stages, but still run build stages, package stages and sanity check stages. Note: Does NOT update GitHub check status.

--stage-list "A10-PyTorch-1, xxx" (OPTIONAL) : Only run the specified test stages. Examples: "A10-PyTorch-1, xxx". Note: Does NOT update GitHub check status.

--gpu-type "A30, H100_PCIe" (OPTIONAL) : Only run the test stages on the specified GPU types. Examples: "A30, H100_PCIe". Note: Does NOT update GitHub check status.

--test-backend "pytorch, cpp" (OPTIONAL) : Skip test stages which don't match the specified backends. Only support [pytorch, cpp, tensorrt, triton]. Examples: "pytorch, cpp" (does not run test stages with tensorrt or triton backend). Note: Does NOT update GitHub pipeline status.

--only-multi-gpu-test (OPTIONAL) : Only run the multi-GPU tests. Note: Does NOT update GitHub check status.

--disable-multi-gpu-test (OPTIONAL) : Disable the multi-GPU tests. Note: Does NOT update GitHub check status.

--add-multi-gpu-test (OPTIONAL) : Force run the multi-GPU tests in addition to running L0 pre-merge pipeline.

--post-merge (OPTIONAL) : Run the L0 post-merge pipeline instead of the ordinary L0 pre-merge pipeline.

--extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx" (OPTIONAL) : Run the ordinary L0 pre-merge pipeline and specified test stages. Examples: --extra-stage "H100_PCIe-TensorRT-Post-Merge-1, xxx".

--detailed-log (OPTIONAL) : Enable flushing out all logs to the Jenkins console. This will significantly increase the log volume and may slow down the job.

--debug (OPTIONAL) : Experimental feature. Enable access to the CI container for debugging purpose. Note: Specify exactly one stage in the stage-list parameter to access the appropriate container environment. Note: Does NOT update GitHub check status.

--high-priority (OPTIONAL) : Run the pipeline with high priority. This option is restricted to authorized users only and will route the job to a high-priority queue.

kill

kill

Kill all running builds associated with pull request.

skip

skip --comment COMMENT

Skip testing for latest commit on pull request. --comment "Reason for skipping build/test" is required. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

reuse-pipeline

reuse-pipeline

Reuse a previous pipeline to validate current commit. This action will also kill all currently running builds associated with the pull request. IMPORTANT NOTE: This is dangerous since lack of user care and validation can cause top of tree to break.

@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai Bot commented Apr 6, 2026

📝 Walkthrough

Walkthrough

A single command parameter modification in a Jenkins Groovy script that adds explicit exclusion of the PIP detector to a pulse scan invocation while preserving the SBOM generation and no-fail behavior.

Changes

Cohort / File(s) Summary
Jenkins Build Script
jenkins/TensorRT_LLM_PLC.groovy
Modified pulse scan command to exclude PIP detector by adding --exclude-detectors PIP flag while maintaining existing --no-fail and --sbom options.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: adding --exclude-detectors PIP to the pulse scan command to fix source code scanning in the infrastructure.
Description check ✅ Passed The description provides a clear explanation of what the change does (disables pip inspector in PLC nightly pipeline) but lacks details on why this change is necessary and test coverage information.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@jenkins/TensorRT_LLM_PLC.groovy`:
- Line 211: Next to the sh invocation "sh 'pulse scan --no-fail
--exclude-detectors PIP --sbom .'", add a concise inline comment that states:
the specific reason PIP detector is disabled (e.g., false positives,
performance, compatibility), whether this exclusion is temporary or permanent,
and if temporary include the mitigation plan and expected re‑enable date or
ticket/issue ID; if permanent explicitly acknowledge and accept the reduced
Python dependency scanning coverage and reference any risk acceptance or
tracking ticket. Ensure the comment is brief but includes the rationale,
permanence, and a link/ID to the tracking ticket or next action.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 3d043c50-4be4-41d0-9d61-1e7a6657ef03

📥 Commits

Reviewing files that changed from the base of the PR and between 662e45f and 72efc0e.

📒 Files selected for processing (1)
  • jenkins/TensorRT_LLM_PLC.groovy

Comment thread jenkins/TensorRT_LLM_PLC.groovy
@yuanjingx87
Copy link
Copy Markdown
Collaborator Author

/bot skip --comment "no need to run CI"

@tensorrt-cicd
Copy link
Copy Markdown
Collaborator

PR_Github #41966 [ skip ] triggered by Bot. Commit: 72efc0e Link to invocation

@tensorrt-cicd
Copy link
Copy Markdown
Collaborator

PR_Github #41966 [ skip ] completed with state SUCCESS. Commit: 72efc0e
Skipping testing for commit 72efc0e

Link to invocation

@yuanjingx87 yuanjingx87 merged commit 9457816 into NVIDIA:main Apr 6, 2026
9 of 10 checks passed
xinhe-nv pushed a commit to xinhe-nv/TensorRT-LLM that referenced this pull request Apr 7, 2026
Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
yufeiwu-nv pushed a commit to yufeiwu-nv/TensorRT-LLM that referenced this pull request Apr 7, 2026
Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
karen-sy pushed a commit to karen-sy/TensorRT-LLM that referenced this pull request Apr 7, 2026
Signed-off-by: Yuanjing Xue <197832395+yuanjingx87@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.