build(wasm): pin the base image digest and verify the fgl tarball - #17
Merged
Merged
Conversation
debian:13-slim was a mutable tag and the pre-seeded fgl tarball was fetched without any integrity check, so either could change the Artifact without a diff in this repository. Pin the base image by digest and let Dependabot's docker ecosystem keep it current. Check the fgl tarball against its Hackage sha256, cross- checked with commercialhaskell/all-cabal-hashes.
|
🎉 This PR is included in version 0.2.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes the two real gaps in #10: the Docker base image was a mutable tag, and the pre-seeded
fgltarball had no integrity check.Changes
buildtools/wasm/Dockerfile:debian:13-slimpinned to its multi-arch index digestsha256:a99cfc51…..github/dependabot.yml: add thedockerecosystem for/buildtools/wasm, so the digest gets weekly bump PRs instead of going stale on security patches.buildtools/wasm/build.sh:sha256sum -cthefgl-5.8.3.1tarball. The hash from Hackage matchescommercialhaskell/all-cabal-hashes.AGENTS.md: the toolchain-bump checklist now mentions the fgl sha256 and namesbuild.sh, not the Dockerfile, as where fgl lives.Not done from #10, on purpose
snapshot.debian.orgavoids that, and it is too slow and flaky for CI. The digest-pinned base image already fixes the package set at build time.fetch-native-shellcheck.shonly fetches the parity reference and is never shipped. Pinning per-OS/arch hashes would also break the dailybump-shellcheck.ymlPRs.provenance: false: deliberate, see the comment in both workflows. If provenance for the release asset is wanted,actions/attest-build-provenanceonshellcheck.wasminrelease.ymlis the right tool. That is a separate decision.Suggest closing #10 with this PR. It is not linked as
Closesso you can decide.Review note
There is no Docker locally, so the changed build path has not run yet. The
build-wasmjob in this PR's CI is the first real check of the digest pull and the fgl verification.