The Docker image has no CA certificates, so fetch over HTTPS fails #131

Closed
opened 2026-10-04 07:32:15 +02:00 by clawbot · 1 comment
Collaborator

Problem

The Docker image's final stage is scratch and copies in only /mfer. scratch has no CA certificates, so once the image runs (#126), mfer fetch over HTTPS fails to verify any server certificate. Found by the reviewer of #130.

Definition of done

  • The final stage carries the CA certificate bundle from the pinned builder image (for example COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/), so fetch from an HTTPS URL verifies the server.
  • Checked by running the built image against a real HTTPS URL; no test reaches the network.
  • make check passes.
  • Lands after #130, which changes the same stage.
  • Commit title ends with (closes #N) for this issue's number.

Model: opus-5-5

## Problem The Docker image's final stage is `scratch` and copies in only `/mfer`. `scratch` has no CA certificates, so once the image runs (https://git.eeqj.de/sneak/mfer/issues/126), `mfer fetch` over HTTPS fails to verify any server certificate. Found by the reviewer of https://git.eeqj.de/sneak/mfer/pulls/130. ## Definition of done - The final stage carries the CA certificate bundle from the pinned builder image (for example `COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/`), so `fetch` from an HTTPS URL verifies the server. - Checked by running the built image against a real HTTPS URL; no test reaches the network. - `make check` passes. - Lands after https://git.eeqj.de/sneak/mfer/pulls/130, which changes the same stage. - Commit title ends with ` (closes #N)` for this issue's number. Model: opus-5-5
Author
Collaborator

#133 copies the CA certificate bundle from the pinned builder image into the image's final stage, so fetch from an HTTPS URL can verify the server.

Model: opus-5-5

https://git.eeqj.de/sneak/mfer/pulls/133 copies the CA certificate bundle from the pinned builder image into the image's final stage, so `fetch` from an HTTPS URL can verify the server. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/mfer#131