Repository navigation
ci: dry-check the mirror list on PRs and write tags only after merge - #4544
Conversation
A PR that changed the image list copied images with its own, unreviewed copy of the script, writing the same tags develop's CI pulls. PRs, forks included, now get a read-only check: each reference resolves on Docker Hub and its digest is compared with the mirror's, reporting what the copy after merge would do. Copies run only on push to develop, dispatch and the weekly schedule. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Peter Amiri <peter@alurium.com>
|
rev1-r3 review @ 1070b56: CHANGES (one line) The split is right, apart from one gap in the write path. Fork PRs are read-only and can't reach the write job.
A crafted list file can't do harm beyond what a fork PR can already do.
The triggers are unchanged: dispatch, the The gap:
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Peter Amiri <peter@alurium.com>
|
rev1-r3 review @ 11d1e7f: APPROVE The one change from my CHANGES at 1070b56 is in:
Everything else is as I reviewed at 1070b56:
PR CI on this head: 25 pass, 4 skipping, 0 fail. That includes |
Summary
Follow-up to #4540. Until now, a same-repo PR that touched the mirror files ran the PR head's
mirror-images.shwithpackages: write, against the same tags develop's CI pulls (for examplemirror/ortussolutions/commandbox:latest). An unreviewed change could therefore repoint a live tag.Now:
checkjob per image with a read-only token (contents: read,packages: read).mirror-images.sh check <ref>resolves the source on Docker Hub with a HEAD, which doesn't count toward the pull limit. It then compares that digest with the mirror's and reports one ofup to date,would copy … (mirror has …)orwould copy … (new image …). It fails only when a source doesn't resolve, or when a digest pin no longer exists upstream. Nothing is written.mirrorjob,packages: write) run only on a push to develop that changes the mirror files, onworkflow_dispatch, and on the weekly schedule.The cost is two steps for a new image: add it to
tools/ci/mirror-images.txtand merge, which mirrors it, then point CI at it in a later PR.Test plan
actionlintandshellcheckare cleanlist+checkjobs; nomirrorjob runs, and each check reportsup to date🤖 Generated with Claude Code