The Docker image's final stage is scratch and copies in only /mfer. scratch has no CA certificates, so once the image runs (#126), mfer fetch over HTTPS fails to verify any server certificate. Found by the reviewer of #130.
Definition of done
The final stage carries the CA certificate bundle from the pinned builder image (for example COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/), so fetch from an HTTPS URL verifies the server.
Checked by running the built image against a real HTTPS URL; no test reaches the network.
Commit title ends with (closes #N) for this issue's number.
Model: opus-5-5
## Problem
The Docker image's final stage is `scratch` and copies in only `/mfer`. `scratch` has no CA certificates, so once the image runs (https://git.eeqj.de/sneak/mfer/issues/126), `mfer fetch` over HTTPS fails to verify any server certificate. Found by the reviewer of https://git.eeqj.de/sneak/mfer/pulls/130.
## Definition of done
- The final stage carries the CA certificate bundle from the pinned builder image (for example `COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/`), so `fetch` from an HTTPS URL verifies the server.
- Checked by running the built image against a real HTTPS URL; no test reaches the network.
- `make check` passes.
- Lands after https://git.eeqj.de/sneak/mfer/pulls/130, which changes the same stage.
- Commit title ends with ` (closes #N)` for this issue's number.
Model: opus-5-5
#133 copies the CA certificate bundle from the pinned builder image into the image's final stage, so fetch from an HTTPS URL can verify the server.
Model: opus-5-5
https://git.eeqj.de/sneak/mfer/pulls/133 copies the CA certificate bundle from the pinned builder image into the image's final stage, so `fetch` from an HTTPS URL can verify the server.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Problem
The Docker image's final stage is
scratchand copies in only/mfer.scratchhas no CA certificates, so once the image runs (#126),mfer fetchover HTTPS fails to verify any server certificate. Found by the reviewer of #130.Definition of done
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/), sofetchfrom an HTTPS URL verifies the server.make checkpasses.(closes #N)for this issue's number.Model: opus-5-5
#133 copies the CA certificate bundle from the pinned builder image into the image's final stage, so
fetchfrom an HTTPS URL can verify the server.Model: opus-5-5