All checks were successful
check / check (push) Successful in 10s
Replacing klakegg/hugo:ext-alpine with the Dockerfile's pinned alpine digest satisfied the pinning requirement but dropped the runtime the Actions runner itself depends on, which would have broken the deploy: - act_runner executes JavaScript actions with `node` inside the job container and does not inject one. Stock alpine has no node, so actions/checkout - the job's first step - would fail with "node: not found", and script/bootstrap (which installs node) is step 2 and never runs. The build job fails, deploy is skipped for `needs: build`, and the site stops publishing. - Steps default to `bash`, which stock alpine does not ship either. Fixes, both scoped to keeping the mandated image replacement runnable: - A pre-checkout inline `run:` step (`apk add --no-cache nodejs git tar`) installs what the runner needs before the first `uses:` step. An inline run needs only a shell, so it works on the bare image. git is there for checkout's `submodules: recursive`; without it checkout degrades to a tarball download that cannot do submodules. - `defaults.run.shell: sh` on the build job, so the shell is stated rather than left to a bash-to-sh fallback. No pinned value is touched. The apk packages resolve at run time and are not hash-pinned; that gap is repo-wide (script/bootstrap has it too) and is tracked in #19. Also moves each version/date comment to sit directly above the pinned line rather than above the step's `- name:`, matching check.yml, and dates the actions/checkout pin 2026-02-28 as check.yml already does for the same SHA. Verified by running the build job's step sequence inside the pinned alpine digest: bare, `node` and `bash` are absent and the pinned checkout bundle dies with "node: not found"; after the new apk step, node 22.23.2, git 2.47.3 and GNU tar 1.35 are present, that same checkout bundle runs under node and gets as far as "GITHUB_WORKSPACE not defined", and script/bootstrap, script/test and the tar step all complete. make check and script/cibuild (with the build cache pruned, so nothing was CACHED) are green.
2.8 KiB
2.8 KiB
Workflow
- branch (from
main) - do the work in Next Step
- move Next Step to the top of Completed Steps
- move the top item of Future Steps into Next Step
- commit (
TODO.mdchanges in the same commit as the work) - merge to
mainif the branch is not protected, otherwise open a PR - push
Status
pre-1.0
No git tags. The site is live and now has the scripts-to-rule-them-all scaffold
(Makefile, script/, Dockerfile, check.yml); still missing LICENSE and
policy files. Every external reference in the repo is now pinned by
cryptographic hash (or, for the wrangler CLI install, an exact version).
Next Step
Add the remaining policy scaffold: LICENSE, REPO_POLICIES.md,
.editorconfig, and prettier config files (.prettierrc, .prettierignore).
Update README.md accordingly.
Completed Steps
- 2026-08-09: hash-pinned every external reference in
.gitea/workflows/deploy.yml(closes #7): both job container images are pinned by digest, all threeuses:are pinned by 40-hex commit SHA (upload/download-artifactmoved v3 to v4), and the wrangler install is pinned to an exact version. The abandonedklakegg/hugo:ext-alpineimage is gone: the build job now runs on the same pinnedalpinedigest theDockerfileuses, with a pre-checkoutapk add nodejs git tarstep (the Actions runner needsnodeinside the job container to execute JavaScript actions), an explicitshell: shdefault, thenscript/bootstrapandscript/test. Also dropped the deadfeat/initial-sitepush trigger and reindented the file to 4-space YAML to matchcheck.yml - 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4):
script/entrypoints,Makefileshims, a HugoDockerfile(sha256-pinned alpine) plus.dockerignorethat runsmake check,.gitea/workflows/check.ymlrunningscript/cibuild, and a README Entrypoints section.test/lintare a cleanhugo --minifybuild;fmt/fmt-checkrun prettier over the repo's own top-level markdown only - 2026-02-10: design pass: minimal light theme with inline CSS, grey wells for mesh channels and signal groups, horizontal overflow fix, body width tuning, map link update
- 2026-02-10: added README and footer contribute link
- 2026-02-10: added Gitea workflow that builds the site and deploys to Cloudflare Pages
- 2026-02-08: initial Hugo static site for lora.vegas
Future Steps
- Rework README.md into the standard sections: Description, Getting Started, Rationale, Design, TODO, License, Author (currently About, Contributing, Technical Details, License)
- Replace the "content is provided as-is" README note with the text of the committed LICENSE
- Expand .gitignore beyond Hugo outputs (OS and editor files)
- Verify the Cloudflare Pages deploy still works after the workflow changes
- Keep mesh channel and signal group listings current