Hash-pin every external reference in deploy.yml (closes #7)
All checks were successful
check / check (push) Successful in 7s
All checks were successful
check / check (push) Successful in 7s
deploy.yml was the last file in the repo carrying mutable external references. Every image is now pinned by digest and every action by a full 40-hex commit SHA, each with a version/date comment on the line above. All values were resolved from upstream and verified to resolve. - build container: klakegg/hugo:ext-alpine (abandoned since 2021, mutable tag) replaced by the exact alpine 3.21 digest the Dockerfile already pins, with script/bootstrap to install hugo and script/test to build. One pinned base and one dependency list now serve both the check build and the deploy build. - deploy container: node:20 -> node@sha256:8f693eaa... (node 20.20.2, bookworm). - actions/checkout: v4 -> 11bd7190... (v4.2.2), the same SHA check.yml pins, so the two workflows agree. - actions/upload-artifact: v3 -> ea165f8d... (v4.6.2); v3 is deprecated. - actions/download-artifact: v3 -> d3f86a10... (v4.3.0); v3 is deprecated. - npm install -g wrangler -> wrangler@4.120.0, so the deploy no longer executes whatever the wrangler tag happens to point at. Also drops the dead feat/initial-site push trigger (that branch is fully merged into main) and reindents the file to 4-space YAML to match check.yml and .editorconfig. The two jobs are deliberately left separate so a deploy regression can be attributed unambiguously. Verified: make check and script/cibuild both green; the workflow parses as YAML with the expected job/step structure. The Cloudflare Pages deploy path itself cannot be exercised from a branch (it runs only on push to main and needs CLOUDFLARE_API_TOKEN), so the deploy run on main must be watched after merge.
This commit is contained in:
15
TODO.md
15
TODO.md
@@ -14,7 +14,8 @@ pre-1.0
|
||||
|
||||
No git tags. The site is live and now has the scripts-to-rule-them-all scaffold
|
||||
(`Makefile`, `script/`, `Dockerfile`, `check.yml`); still missing `LICENSE` and
|
||||
policy files.
|
||||
policy files. Every external reference in the repo is now pinned by
|
||||
cryptographic hash (or, for the wrangler CLI install, an exact version).
|
||||
|
||||
# Next Step
|
||||
|
||||
@@ -24,6 +25,15 @@ Update `README.md` accordingly.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-09: hash-pinned every external reference in
|
||||
`.gitea/workflows/deploy.yml` (closes #7): both job container images are
|
||||
pinned by digest, all three `uses:` are pinned by 40-hex commit SHA
|
||||
(`upload`/`download-artifact` moved v3 to v4), and the wrangler install is
|
||||
pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is
|
||||
gone: the build job now runs on the same pinned `alpine` digest the
|
||||
`Dockerfile` uses, with `script/bootstrap` then `script/test`. Also dropped
|
||||
the dead `feat/initial-site` push trigger and reindented the file to 4-space
|
||||
YAML to match `check.yml`
|
||||
- 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/`
|
||||
entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus
|
||||
`.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running
|
||||
@@ -40,9 +50,6 @@ Update `README.md` accordingly.
|
||||
|
||||
# Future Steps
|
||||
|
||||
- Pin the images and actions in `deploy.yml` by sha256
|
||||
(`klakegg/hugo:ext-alpine`, `node:20`, `actions/checkout`,
|
||||
`upload`/`download-artifact` are all unpinned)
|
||||
- Rework README.md into the standard sections: Description, Getting Started,
|
||||
Rationale, Design, TODO, License, Author (currently About, Contributing,
|
||||
Technical Details, License)
|
||||
|
||||
Reference in New Issue
Block a user