Copies the CA certificate bundle from the pinned builder image (/etc/ssl/certs/ca-certificates.crt) into the scratch final stage. scratch has no certificates, so mfer fetch from any HTTPS URL failed with "certificate signed by unknown authority". Go looks for the bundle at that path by default, so no environment variable or code change is needed.
The bundle is the one the pinned golang builder image ships, so it is refreshed only when that pin is bumped.
Builds on #130, which made the binary static so the image runs.
Unverified item: the built image was run against a real HTTPS server at a URL with no index.mf, so certificate verification was exercised but a full download over HTTPS was not.
No automated test: the change is in the image only, and no test reaches the network.
Model: opus-5-5
Copies the CA certificate bundle from the pinned builder image (`/etc/ssl/certs/ca-certificates.crt`) into the `scratch` final stage. `scratch` has no certificates, so `mfer fetch` from any HTTPS URL failed with "certificate signed by unknown authority". Go looks for the bundle at that path by default, so no environment variable or code change is needed.
The bundle is the one the pinned `golang` builder image ships, so it is refreshed only when that pin is bumped.
Builds on https://git.eeqj.de/sneak/mfer/pulls/130, which made the binary static so the image runs.
Closes https://git.eeqj.de/sneak/mfer/issues/131
- Unverified item: the built image was run against a real HTTPS server at a URL with no `index.mf`, so certificate verification was exercised but a full download over HTTPS was not.
- No automated test: the change is in the image only, and no test reaches the network.
Model: opus-5-5
The final stage is scratch, which has no CA certificates, so fetch from
an HTTPS URL failed to verify any server. Copy the CA bundle from the
pinned builder image into the final stage.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Copies the CA certificate bundle from the pinned builder image (
/etc/ssl/certs/ca-certificates.crt) into thescratchfinal stage.scratchhas no certificates, somfer fetchfrom any HTTPS URL failed with "certificate signed by unknown authority". Go looks for the bundle at that path by default, so no environment variable or code change is needed.The bundle is the one the pinned
golangbuilder image ships, so it is refreshed only when that pin is bumped.Builds on #130, which made the binary static so the image runs.
Closes #131
index.mf, so certificate verification was exercised but a full download over HTTPS was not.Model: opus-5-5
Review passed.
Gated on
nextat64eb5cb.Model: opus-5-5