Hash-pin every external reference in deploy.yml (closes #7) #17

Merged
clawbot merged 2 commits from pin-deploy-workflow-refs into main 2026-08-09 04:28:21 +02:00
2 changed files with 84 additions and 44 deletions

View File

@@ -3,28 +3,56 @@ name: Build and Deploy to Cloudflare Pages
on:
push:
branches:
- feat/initial-site
- main
jobs:
build:
runs-on: ubuntu-latest
container:
image: klakegg/hugo:ext-alpine
# Same digest the Dockerfile pins: one pinned base image and the
# same dependency list (script/bootstrap) for both the check build
# and the deploy build. The one extra thing this job needs on top
# of the Dockerfile is the Actions runner's own prerequisites --
# see the first step.
# alpine 3.21, 2026-02-28
image: alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
defaults:
run:
# The default step shell is bash; this image has only busybox
# sh, so say so explicitly rather than rely on a fallback.
shell: sh
steps:
# This image is bare busybox+musl. act_runner executes JavaScript
# actions (checkout, upload-artifact) with `node` *inside* the job
# container and does not inject one, so node has to exist before
# the first `uses:` step -- script/bootstrap runs too late. git is
# needed for checkout's `submodules: recursive` (without it
# checkout degrades to a tarball download that cannot do
# submodules). An inline `run:` needs only a shell, so this step
# works on the bare image. These apk packages resolve at run time
# and are not hash-pinned; that gap is repo-wide (script/bootstrap
# has it too) and is tracked in #19.
- name: Install runner prerequisites
run: apk add --no-cache nodejs git tar
- name: Checkout
uses: actions/checkout@v4
# actions/checkout v4.2.2, 2026-02-28
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
submodules: recursive
- name: Install build dependencies
run: script/bootstrap
- name: Build site
run: hugo --minify
run: script/test
- name: Archive site
run: tar -czf site.tar.gz public
- name: Upload artifact
uses: actions/upload-artifact@v3
# actions/upload-artifact v4.6.2, 2026-08-09
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: site
path: site.tar.gz
@@ -33,10 +61,12 @@ jobs:
runs-on: ubuntu-latest
needs: build
container:
image: node:20
# node 20.20.2-bookworm, 2026-08-09
image: node@sha256:8f693eaa7e0a8e71560c9a82b55fd54c2ae920a2ba5d2cde28bac7d1c01c9ba5
steps:
- name: Download artifact
uses: actions/download-artifact@v3
# actions/download-artifact v4.3.0, 2026-08-09
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
with:
name: site
@@ -44,7 +74,8 @@ jobs:
run: tar -xzf site.tar.gz
- name: Install Wrangler
run: npm install -g wrangler
# wrangler 4.120.0, 2026-08-09
run: npm install -g wrangler@4.120.0
- name: Deploy to Cloudflare Pages
run: wrangler pages deploy public --project-name=lora-vegas --branch=${{ github.ref_name }}

17
TODO.md
View File

@@ -14,7 +14,8 @@ pre-1.0
No git tags. The site is live and now has the scripts-to-rule-them-all scaffold
(`Makefile`, `script/`, `Dockerfile`, `check.yml`); still missing `LICENSE` and
policy files.
policy files. Every external reference in the repo is now pinned by
cryptographic hash (or, for the wrangler CLI install, an exact version).
# Next Step
@@ -24,6 +25,17 @@ Update `README.md` accordingly.
# Completed Steps
- 2026-08-09: hash-pinned every external reference in
`.gitea/workflows/deploy.yml` (closes #7): both job container images are
pinned by digest, all three `uses:` are pinned by 40-hex commit SHA
(`upload`/`download-artifact` moved v3 to v4), and the wrangler install is
pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is
gone: the build job now runs on the same pinned `alpine` digest the
`Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the
Actions runner needs `node` inside the job container to execute JavaScript
actions), an explicit `shell: sh` default, then `script/bootstrap` and
`script/test`. Also dropped the dead `feat/initial-site` push trigger and
reindented the file to 4-space YAML to match `check.yml`
- 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/`
entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus
`.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running
@@ -40,9 +52,6 @@ Update `README.md` accordingly.
# Future Steps
- Pin the images and actions in `deploy.yml` by sha256
(`klakegg/hugo:ext-alpine`, `node:20`, `actions/checkout`,
`upload`/`download-artifact` are all unpinned)
- Rework README.md into the standard sections: Description, Getting Started,
Rationale, Design, TODO, License, Author (currently About, Contributing,
Technical Details, License)