Hash-pin every external reference in deploy.yml (closes #7) #17
@@ -9,14 +9,34 @@ jobs:
|
|||||||
build:
|
build:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
container:
|
container:
|
||||||
# Same digest the Dockerfile pins: one pinned base image and one
|
# Same digest the Dockerfile pins: one pinned base image and the
|
||||||
# dependency list (script/bootstrap) for both the check build and
|
# same dependency list (script/bootstrap) for both the check build
|
||||||
# the deploy build.
|
# and the deploy build. The one extra thing this job needs on top
|
||||||
|
# of the Dockerfile is the Actions runner's own prerequisites --
|
||||||
|
# see the first step.
|
||||||
# alpine 3.21, 2026-02-28
|
# alpine 3.21, 2026-02-28
|
||||||
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
||||||
|
defaults:
|
||||||
|
run:
|
||||||
|
# The default step shell is bash; this image has only busybox
|
||||||
|
# sh, so say so explicitly rather than rely on a fallback.
|
||||||
|
shell: sh
|
||||||
steps:
|
steps:
|
||||||
# actions/checkout v4.2.2, 2026-08-09
|
# This image is bare busybox+musl. act_runner executes JavaScript
|
||||||
|
# actions (checkout, upload-artifact) with `node` *inside* the job
|
||||||
|
# container and does not inject one, so node has to exist before
|
||||||
|
# the first `uses:` step -- script/bootstrap runs too late. git is
|
||||||
|
# needed for checkout's `submodules: recursive` (without it
|
||||||
|
# checkout degrades to a tarball download that cannot do
|
||||||
|
# submodules). An inline `run:` needs only a shell, so this step
|
||||||
|
# works on the bare image. These apk packages resolve at run time
|
||||||
|
# and are not hash-pinned; that gap is repo-wide (script/bootstrap
|
||||||
|
# has it too) and is tracked in #19.
|
||||||
|
- name: Install runner prerequisites
|
||||||
|
run: apk add --no-cache nodejs git tar
|
||||||
|
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
|
# actions/checkout v4.2.2, 2026-02-28
|
||||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||||
with:
|
with:
|
||||||
submodules: recursive
|
submodules: recursive
|
||||||
@@ -30,8 +50,8 @@ jobs:
|
|||||||
- name: Archive site
|
- name: Archive site
|
||||||
run: tar -czf site.tar.gz public
|
run: tar -czf site.tar.gz public
|
||||||
|
|
||||||
# actions/upload-artifact v4.6.2, 2026-08-09
|
|
||||||
- name: Upload artifact
|
- name: Upload artifact
|
||||||
|
# actions/upload-artifact v4.6.2, 2026-08-09
|
||||||
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
|
||||||
with:
|
with:
|
||||||
name: site
|
name: site
|
||||||
@@ -44,8 +64,8 @@ jobs:
|
|||||||
# node 20.20.2-bookworm, 2026-08-09
|
# node 20.20.2-bookworm, 2026-08-09
|
||||||
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
|
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
|
||||||
steps:
|
steps:
|
||||||
# actions/download-artifact v4.3.0, 2026-08-09
|
|
||||||
- name: Download artifact
|
- name: Download artifact
|
||||||
|
# actions/download-artifact v4.3.0, 2026-08-09
|
||||||
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
|
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
|
||||||
with:
|
with:
|
||||||
name: site
|
name: site
|
||||||
@@ -53,8 +73,8 @@ jobs:
|
|||||||
- name: Extract site
|
- name: Extract site
|
||||||
run: tar -xzf site.tar.gz
|
run: tar -xzf site.tar.gz
|
||||||
|
|
||||||
# wrangler 4.120.0, 2026-08-09
|
|
||||||
- name: Install Wrangler
|
- name: Install Wrangler
|
||||||
|
# wrangler 4.120.0, 2026-08-09
|
||||||
run: npm install -g wrangler@4.120.0
|
run: npm install -g wrangler@4.120.0
|
||||||
|
|
||||||
- name: Deploy to Cloudflare Pages
|
- name: Deploy to Cloudflare Pages
|
||||||
|
|||||||
8
TODO.md
8
TODO.md
@@ -31,9 +31,11 @@ Update `README.md` accordingly.
|
|||||||
(`upload`/`download-artifact` moved v3 to v4), and the wrangler install is
|
(`upload`/`download-artifact` moved v3 to v4), and the wrangler install is
|
||||||
pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is
|
pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is
|
||||||
gone: the build job now runs on the same pinned `alpine` digest the
|
gone: the build job now runs on the same pinned `alpine` digest the
|
||||||
`Dockerfile` uses, with `script/bootstrap` then `script/test`. Also dropped
|
`Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the
|
||||||
the dead `feat/initial-site` push trigger and reindented the file to 4-space
|
Actions runner needs `node` inside the job container to execute JavaScript
|
||||||
YAML to match `check.yml`
|
actions), an explicit `shell: sh` default, then `script/bootstrap` and
|
||||||
|
`script/test`. Also dropped the dead `feat/initial-site` push trigger and
|
||||||
|
reindented the file to 4-space YAML to match `check.yml`
|
||||||
- 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/`
|
- 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/`
|
||||||
entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus
|
entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus
|
||||||
`.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running
|
`.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running
|
||||||
|
|||||||
Reference in New Issue
Block a user