From 588c1bae745eff116dc5a366914e0c81e371c343 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 10:31:54 +0200 Subject: [PATCH] Give the image CA certificates so fetch works over HTTPS (closes #131) The final stage is scratch, which has no CA certificates, so fetch from an HTTPS URL failed to verify any server. Copy the CA bundle from the pinned builder image into the final stage. Model: opus-5-5 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index 34d9d4b..26a9592 100644 --- a/Dockerfile +++ b/Dockerfile @@ -75,5 +75,7 @@ RUN version="${VERSION:-$(git describe --tags --always)}"; \ RUN ldd /mfer 2>&1 | grep -q 'not a dynamic executable' FROM scratch +# scratch has no CA certificates; fetch needs them to verify HTTPS servers. +COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ COPY --from=builder /mfer /mfer ENTRYPOINT ["/mfer"]