Skip to content

build(wasm): pin the base image digest and verify the fgl tarball - #17

Merged
timonwong merged 2 commits into
mainfrom
build/pin-base-image-and-fgl-checksum
Sep 21, 2026
Merged

timonwong merged 2 commits into
mainfrom
build/pin-base-image-and-fgl-checksum

Conversation

@timonwong

Copy link
Copy Markdown
Member

Summary

Closes the two real gaps in #10: the Docker base image was a mutable tag, and the pre-seeded fgl tarball had no integrity check.

Changes

  • buildtools/wasm/Dockerfile: debian:13-slim pinned to its multi-arch index digest sha256:a99cfc51….
  • .github/dependabot.yml: add the docker ecosystem for /buildtools/wasm, so the digest gets weekly bump PRs instead of going stale on security patches.
  • buildtools/wasm/build.sh: sha256sum -c the fgl-5.8.3.1 tarball. The hash from Hackage matches commercialhaskell/all-cabal-hashes.
  • AGENTS.md: the toolchain-bump checklist now mentions the fgl sha256 and names build.sh, not the Dockerfile, as where fgl lives.

Not done from #10, on purpose

  • ghc-wasm-meta checksum: the archive URL is already pinned to a commit SHA.
  • apt version pins: Debian drops old package versions from the mirrors, so pins break builds within weeks. Only snapshot.debian.org avoids that, and it is too slow and flaky for CI. The digest-pinned base image already fixes the package set at build time.
  • Native ShellCheck checksum: fetch-native-shellcheck.sh only fetches the parity reference and is never shipped. Pinning per-OS/arch hashes would also break the daily bump-shellcheck.yml PRs.
  • provenance: false: deliberate, see the comment in both workflows. If provenance for the release asset is wanted, actions/attest-build-provenance on shellcheck.wasm in release.yml is the right tool. That is a separate decision.

Suggest closing #10 with this PR. It is not linked as Closes so you can decide.

Review note

There is no Docker locally, so the changed build path has not run yet. The build-wasm job in this PR's CI is the first real check of the digest pull and the fgl verification.

debian:13-slim was a mutable tag and the pre-seeded fgl tarball was
fetched without any integrity check, so either could change the
Artifact without a diff in this repository.

Pin the base image by digest and let Dependabot's docker ecosystem keep
it current. Check the fgl tarball against its Hackage sha256, cross-
checked with commercialhaskell/all-cabal-hashes.
@timonwong
timonwong enabled auto-merge (squash) September 21, 2026 12:03
@timonwong
timonwong merged commit 349a7e1 into main Sep 21, 2026
3 checks passed
@timonwong
timonwong deleted the build/pin-base-image-and-fgl-checksum branch September 21, 2026 12:13
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 0.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant