Hash-pin every external reference in deploy.yml (closes #7)
All checks were successful
check / check (push) Successful in 7s
All checks were successful
check / check (push) Successful in 7s
deploy.yml was the last file in the repo carrying mutable external references. Every image is now pinned by digest and every action by a full 40-hex commit SHA, each with a version/date comment on the line above. All values were resolved from upstream and verified to resolve. - build container: klakegg/hugo:ext-alpine (abandoned since 2021, mutable tag) replaced by the exact alpine 3.21 digest the Dockerfile already pins, with script/bootstrap to install hugo and script/test to build. One pinned base and one dependency list now serve both the check build and the deploy build. - deploy container: node:20 -> node@sha256:8f693eaa... (node 20.20.2, bookworm). - actions/checkout: v4 -> 11bd7190... (v4.2.2), the same SHA check.yml pins, so the two workflows agree. - actions/upload-artifact: v3 -> ea165f8d... (v4.6.2); v3 is deprecated. - actions/download-artifact: v3 -> d3f86a10... (v4.3.0); v3 is deprecated. - npm install -g wrangler -> wrangler@4.120.0, so the deploy no longer executes whatever the wrangler tag happens to point at. Also drops the dead feat/initial-site push trigger (that branch is fully merged into main) and reindents the file to 4-space YAML to match check.yml and .editorconfig. The two jobs are deliberately left separate so a deploy regression can be attributed unambiguously. Verified: make check and script/cibuild both green; the workflow parses as YAML with the expected job/step structure. The Cloudflare Pages deploy path itself cannot be exercised from a branch (it runs only on push to main and needs CLOUDFLARE_API_TOKEN), so the deploy run on main must be watched after merge.
This commit is contained in:
@@ -1,52 +1,63 @@
|
||||
name: Build and Deploy to Cloudflare Pages
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- feat/initial-site
|
||||
- main
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: klakegg/hugo:ext-alpine
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
# Same digest the Dockerfile pins: one pinned base image and one
|
||||
# dependency list (script/bootstrap) for both the check build and
|
||||
# the deploy build.
|
||||
# alpine 3.21, 2026-02-28
|
||||
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
||||
steps:
|
||||
# actions/checkout v4.2.2, 2026-08-09
|
||||
- name: Checkout
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||
with:
|
||||
submodules: recursive
|
||||
|
||||
- name: Build site
|
||||
run: hugo --minify
|
||||
- name: Install build dependencies
|
||||
run: script/bootstrap
|
||||
|
||||
- name: Archive site
|
||||
run: tar -czf site.tar.gz public
|
||||
- name: Build site
|
||||
run: script/test
|
||||
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v3
|
||||
with:
|
||||
name: site
|
||||
path: site.tar.gz
|
||||
- name: Archive site
|
||||
run: tar -czf site.tar.gz public
|
||||
|
||||
deploy:
|
||||
runs-on: ubuntu-latest
|
||||
needs: build
|
||||
container:
|
||||
image: node:20
|
||||
steps:
|
||||
- name: Download artifact
|
||||
uses: actions/download-artifact@v3
|
||||
with:
|
||||
name: site
|
||||
# actions/upload-artifact v4.6.2, 2026-08-09
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
|
||||
with:
|
||||
name: site
|
||||
path: site.tar.gz
|
||||
|
||||
- name: Extract site
|
||||
run: tar -xzf site.tar.gz
|
||||
deploy:
|
||||
runs-on: ubuntu-latest
|
||||
needs: build
|
||||
container:
|
||||
# node 20.20.2-bookworm, 2026-08-09
|
||||
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
|
||||
steps:
|
||||
# actions/download-artifact v4.3.0, 2026-08-09
|
||||
- name: Download artifact
|
||||
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
|
||||
with:
|
||||
name: site
|
||||
|
||||
- name: Install Wrangler
|
||||
run: npm install -g wrangler
|
||||
- name: Extract site
|
||||
run: tar -xzf site.tar.gz
|
||||
|
||||
- name: Deploy to Cloudflare Pages
|
||||
run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }}
|
||||
env:
|
||||
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
# wrangler 4.120.0, 2026-08-09
|
||||
- name: Install Wrangler
|
||||
run: npm install -g wrangler@4.120.0
|
||||
|
||||
- name: Deploy to Cloudflare Pages
|
||||
run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }}
|
||||
env:
|
||||
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
|
||||
Reference in New Issue
Block a user