All checks were successful
check / check (push) Successful in 10s
Replacing klakegg/hugo:ext-alpine with the Dockerfile's pinned alpine digest satisfied the pinning requirement but dropped the runtime the Actions runner itself depends on, which would have broken the deploy: - act_runner executes JavaScript actions with `node` inside the job container and does not inject one. Stock alpine has no node, so actions/checkout - the job's first step - would fail with "node: not found", and script/bootstrap (which installs node) is step 2 and never runs. The build job fails, deploy is skipped for `needs: build`, and the site stops publishing. - Steps default to `bash`, which stock alpine does not ship either. Fixes, both scoped to keeping the mandated image replacement runnable: - A pre-checkout inline `run:` step (`apk add --no-cache nodejs git tar`) installs what the runner needs before the first `uses:` step. An inline run needs only a shell, so it works on the bare image. git is there for checkout's `submodules: recursive`; without it checkout degrades to a tarball download that cannot do submodules. - `defaults.run.shell: sh` on the build job, so the shell is stated rather than left to a bash-to-sh fallback. No pinned value is touched. The apk packages resolve at run time and are not hash-pinned; that gap is repo-wide (script/bootstrap has it too) and is tracked in #19. Also moves each version/date comment to sit directly above the pinned line rather than above the step's `- name:`, matching check.yml, and dates the actions/checkout pin 2026-02-28 as check.yml already does for the same SHA. Verified by running the build job's step sequence inside the pinned alpine digest: bare, `node` and `bash` are absent and the pinned checkout bundle dies with "node: not found"; after the new apk step, node 22.23.2, git 2.47.3 and GNU tar 1.35 are present, that same checkout bundle runs under node and gets as far as "GITHUB_WORKSPACE not defined", and script/bootstrap, script/test and the tar step all complete. make check and script/cibuild (with the build cache pruned, so nothing was CACHED) are green.
63 lines
2.8 KiB
Markdown
63 lines
2.8 KiB
Markdown
# Workflow
|
|
|
|
- branch (from `main`)
|
|
- do the work in Next Step
|
|
- move Next Step to the top of Completed Steps
|
|
- move the top item of Future Steps into Next Step
|
|
- commit (`TODO.md` changes in the same commit as the work)
|
|
- merge to `main` if the branch is not protected, otherwise open a PR
|
|
- push
|
|
|
|
# Status
|
|
|
|
pre-1.0
|
|
|
|
No git tags. The site is live and now has the scripts-to-rule-them-all scaffold
|
|
(`Makefile`, `script/`, `Dockerfile`, `check.yml`); still missing `LICENSE` and
|
|
policy files. Every external reference in the repo is now pinned by
|
|
cryptographic hash (or, for the wrangler CLI install, an exact version).
|
|
|
|
# Next Step
|
|
|
|
Add the remaining policy scaffold: `LICENSE`, `REPO_POLICIES.md`,
|
|
`.editorconfig`, and prettier config files (`.prettierrc`, `.prettierignore`).
|
|
Update `README.md` accordingly.
|
|
|
|
# Completed Steps
|
|
|
|
- 2026-08-09: hash-pinned every external reference in
|
|
`.gitea/workflows/deploy.yml` (closes #7): both job container images are
|
|
pinned by digest, all three `uses:` are pinned by 40-hex commit SHA
|
|
(`upload`/`download-artifact` moved v3 to v4), and the wrangler install is
|
|
pinned to an exact version. The abandoned `klakegg/hugo:ext-alpine` image is
|
|
gone: the build job now runs on the same pinned `alpine` digest the
|
|
`Dockerfile` uses, with a pre-checkout `apk add nodejs git tar` step (the
|
|
Actions runner needs `node` inside the job container to execute JavaScript
|
|
actions), an explicit `shell: sh` default, then `script/bootstrap` and
|
|
`script/test`. Also dropped the dead `feat/initial-site` push trigger and
|
|
reindented the file to 4-space YAML to match `check.yml`
|
|
- 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): `script/`
|
|
entrypoints, `Makefile` shims, a Hugo `Dockerfile` (sha256-pinned alpine) plus
|
|
`.dockerignore` that runs `make check`, `.gitea/workflows/check.yml` running
|
|
`script/cibuild`, and a README Entrypoints section. `test`/`lint` are a clean
|
|
`hugo --minify` build; `fmt`/`fmt-check` run prettier over the repo's own
|
|
top-level markdown only
|
|
- 2026-02-10: design pass: minimal light theme with inline CSS, grey wells for
|
|
mesh channels and signal groups, horizontal overflow fix, body width tuning,
|
|
map link update
|
|
- 2026-02-10: added README and footer contribute link
|
|
- 2026-02-10: added Gitea workflow that builds the site and deploys to
|
|
Cloudflare Pages
|
|
- 2026-02-08: initial Hugo static site for lora.vegas
|
|
|
|
# Future Steps
|
|
|
|
- Rework README.md into the standard sections: Description, Getting Started,
|
|
Rationale, Design, TODO, License, Author (currently About, Contributing,
|
|
Technical Details, License)
|
|
- Replace the "content is provided as-is" README note with the text of the
|
|
committed LICENSE
|
|
- Expand .gitignore beyond Hugo outputs (OS and editor files)
|
|
- Verify the Cloudflare Pages deploy still works after the workflow changes
|
|
- Keep mesh channel and signal group listings current
|