ci: check the Pin against Upstream with make verify-pin before the cached build #26
No reviewers
Labels
No labels
bug
enhancement
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
vicoli-oss/docker-forgejo-mcp!26
Loading…
Reference in a new issue
No description provided.
Delete branch "piscis/forgejo-25-verify-pin"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #25
What
make verify-pinresolves the Upstream Version's tag on Upstream withgit ls-remoteand compares it with the Pin'sUPSTREAM_COMMIT. It uses the peeled refrefs/tags/<version>^{}(annotated tags) and falls back torefs/tags/<version>(lightweight tags). It fails if the tag doesn't exist, and on a mismatch with the same message as the Dockerfile check.UPSTREAM_REPOin the Makefile.make buildpasses it as--build-arg UPSTREAM_REPO=..., so the two checks read the same repo. The Dockerfile keeps itsARG UPSTREAM_REPOdefault for a plaindocker build.cirunsmake verify-pinin the job container before "Build the Image". It doesn't use the build cache, so a moved tag turns CI red even when the build is cached.Verified
Locally:
make verify-pinwith the real Pin passes:Upstream tag v3.2.0 resolves to e30bb7e…, as the Pin expects.UPSTREAM_COMMIT=0000…fails with the Dockerfile's wording.UPSTREAM_VERSION=v9.9.9fails withUpstream tag v9.9.9 not found.In CI:
64d86e4): green with a warm cache.verify-pinpasses, and the build's clone-and-verify step isCACHED, which is exactly the case #25 is about.3bdd5ad,UPSTREAM_COMMITset to the tag object931a525…): red at "Verify the Pin against Upstream", before any build ran:3911410reverts the throwaway commit (same pattern as 68e52e5/c76070e). Run 32 on it is green.Follow-up: #7's publish workflow should run
make verify-pinbefore building too (noted on #7).3bdd5ad)